Researchers at the University of California San Diego disclosed severe flaws in the dealer-installed aftermarket KARR Security System, a Bluetooth-enabled alarm and anti-theft device estimated to be present in more than 2 million U.S. vehicles. The vulnerabilities allow an attacker within Bluetooth range to silently unlock doors, disable alarms, trigger horns and lights, and even block the engine from starting, creating both theft and roadside immobilization risks. The researchers said the issue stems in part from a shared embedded authentication key used across KARR devices, which they extracted by reverse-engineering the official mobile app and validating with a proof-of-concept Android tool.
The findings also raised privacy concerns because KARR devices broadcast identifiable Bluetooth signals that could be correlated with public WiGLE data to estimate deployment and potentially infer vehicle movements or frequently visited locations. Acrisure Protection Group, which sells the KARR system, released a firmware update after responsible disclosure, but remediation requires owners or dealerships to identify the hardware and manually apply the patch through the KARR smartphone app. Researchers warned that many drivers may not realize the device is installed, because it is often added by dealerships and can remain in vehicles after resale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers from the University of California San Diego reported vulnerabilities in the aftermarket KARR Security System to Acrisure through responsible disclosure. The disclosure occurred in January 2025, according to the reporting.
Researchers disclosed that severe flaws in the dealer-installed KARR Security System could let an attacker within Bluetooth range unlock cars, disable alarms, honk horns, flash lights, and immobilize vehicles. They also reported that all devices shared the same embedded authentication key and that they built a proof-of-concept Android app after reverse-engineering the official KARR mobile app.
Acrisure Protection Group released a firmware update to address vulnerabilities in the Bluetooth-enabled KARR Security System. The patch requires vehicle owners to manually update affected devices through the KARR Security mobile app.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcescworld.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcetoday.ucsd.edu
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.