Researchers at the University of California San Diego disclosed severe flaws in the dealer-installed aftermarket KARR Security System, a Bluetooth-enabled alarm and anti-theft device estimated to be present in more than 2 million U.S. vehicles. The vulnerabilities allow an attacker within Bluetooth range to silently unlock doors, disable alarms, trigger horns and lights, and even block the engine from starting, creating both theft and roadside immobilization risks. The researchers said the issue stems in part from a shared embedded authentication key used across KARR devices, which they extracted by reverse-engineering the official mobile app and validating with a proof-of-concept Android tool.
The findings also raised privacy concerns because KARR devices broadcast identifiable Bluetooth signals that could be correlated with public WiGLE data to estimate deployment and potentially infer vehicle movements or frequently visited locations. Acrisure Protection Group, which sells the KARR system, released a firmware update after responsible disclosure, but remediation requires owners or dealerships to identify the hardware and manually apply the patch through the KARR smartphone app. Researchers warned that many drivers may not realize the device is installed, because it is often added by dealerships and can remain in vehicles after resale.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers from the University of California San Diego reported vulnerabilities in the aftermarket KARR Security System to Acrisure through responsible disclosure. The disclosure occurred in January 2025, according to the reporting.
Researchers disclosed that severe flaws in the dealer-installed KARR Security System could let an attacker within Bluetooth range unlock cars, disable alarms, honk horns, flash lights, and immobilize vehicles. They also reported that all devices shared the same embedded authentication key and that they built a proof-of-concept Android app after reverse-engineering the official KARR mobile app.
Acrisure Protection Group released a firmware update to address vulnerabilities in the Bluetooth-enabled KARR Security System. The patch requires vehicle owners to manually update affected devices through the KARR Security mobile app.
UC San Diego researchers reported discovering a publicly accessible online database containing information about vehicles equipped with KARR and SWDS aftermarket security systems. The reference does not specify when the database was found.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcethecyberexpress.com
Open sourcescworld.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcetoday.ucsd.edu
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.