Friday, July 31, 2026

Independent technology reporting and practical analysis

Manila ·
TECHNOLOGY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Technology / news

2.2 Million Vehicles at Risk of Remote Hijack via Bluetooth Security Flaw

A hardcoded key in dealer-installed KARR and SWDS anti-theft systems allows attackers to unlock and control cars from Honda, Toyota, Ford, and others.

A smartphone mounted beside a car infotainment system with Bluetooth settings visible. Photo by your_mamacita on Unsplash.
A smartphone mounted beside a car infotainment system with Bluetooth settings visible. Photo by your_mamacita on Unsplash.

A widespread vulnerability in aftermarket vehicle security systems sold by Acrisure could allow attackers to remotely control millions of cars via Bluetooth, according to new research from the University of California San Diego. The flaw affects an estimated 2.2 million vehicles equipped with KARR and SWDS anti-theft and tracking devices, which were installed by dealerships primarily in Southern California since 2017.

The researchers found that the KARR system’s mobile app communicates with the in-car hardware using a shared, static security key. Once an attacker extracts this key from any single device, they can connect to any other vulnerable unit within Bluetooth range and issue commands such as unlocking doors, honking the horn, flashing headlights, or preventing the vehicle from starting if it is not already running. The same key appears to be used across all affected installations, leaving the entire fleet exposed.

Compounding the risk, the team discovered a publicly accessible online database containing details of all vehicles with the security system installed. This could enable attackers to identify and locate high-value targets.

The affected vehicles—spanning Honda, Toyota, Mazda, Ford, and Jeep models—bear a “KARR-SWDS” sticker on the driver-side window, with the device mounted under the dashboard. Even owners who never subscribed to the accompanying app remain vulnerable, as the hardware continues to have full access to the car’s door locks, ignition, horn, and lights.

Fixing the problem poses significant challenges. Changing the shared key is not possible through a software update, and the Bluetooth module cannot be disabled by the user. Physical removal is also difficult. “Removing the devices is not trivial,” said Yibo Wei, a UC San Diego PhD candidate and co-author of the study. “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”

Fellow researcher Jerry Yu noted the low barrier for exploitation: “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”

The manufacturer, KARR, has pushed back on the scale of the issue, stating that only vehicles installed “with certain Bluetooth-related components” are affected and that a firmware update has been released. However, the researchers maintain that the fundamental key reuse problem cannot be resolved without replacing the hardware. The full study is scheduled for publication in August.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Spotify brand mark in green, used to represent the Running Mode feature. Brand icon via Simple Icons.
Software

Spotify’s New Running Mode Uses AI to Curate Workout Playlists

Xbox brand logo representing the console service outage. Brand icon via Simple Icons.
Gaming

Xbox Outage Prevents Disc-Based Play, Fueling Digital Ownership Fears

Google Play brand mark representing the Play Signal API. Brand icon via Simple Icons.
Software

Google to Roll Out Play Signal API Globally by End of 2026 for Age Assurance