
A widespread vulnerability in aftermarket vehicle security systems sold by Acrisure could allow attackers to remotely control millions of cars via Bluetooth, according to new research from the University of California San Diego. The flaw affects an estimated 2.2 million vehicles equipped with KARR and SWDS anti-theft and tracking devices, which were installed by dealerships primarily in Southern California since 2017.
The researchers found that the KARR system’s mobile app communicates with the in-car hardware using a shared, static security key. Once an attacker extracts this key from any single device, they can connect to any other vulnerable unit within Bluetooth range and issue commands such as unlocking doors, honking the horn, flashing headlights, or preventing the vehicle from starting if it is not already running. The same key appears to be used across all affected installations, leaving the entire fleet exposed.
Compounding the risk, the team discovered a publicly accessible online database containing details of all vehicles with the security system installed. This could enable attackers to identify and locate high-value targets.
The affected vehicles—spanning Honda, Toyota, Mazda, Ford, and Jeep models—bear a “KARR-SWDS” sticker on the driver-side window, with the device mounted under the dashboard. Even owners who never subscribed to the accompanying app remain vulnerable, as the hardware continues to have full access to the car’s door locks, ignition, horn, and lights.
Fixing the problem poses significant challenges. Changing the shared key is not possible through a software update, and the Bluetooth module cannot be disabled by the user. Physical removal is also difficult. “Removing the devices is not trivial,” said Yibo Wei, a UC San Diego PhD candidate and co-author of the study. “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”
Fellow researcher Jerry Yu noted the low barrier for exploitation: “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”
The manufacturer, KARR, has pushed back on the scale of the issue, stating that only vehicles installed “with certain Bluetooth-related components” are affected and that a firmware update has been released. However, the researchers maintain that the fundamental key reuse problem cannot be resolved without replacing the hardware. The full study is scheduled for publication in August.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST