Bluetooth Alarm Flaw Puts Millions of Cars at Risk of Remote Unlock and Disable

UCSD researchers uncovered a Bluetooth‑based vulnerability in the aftermarket KARR alarm system—installed in over two million vehicles—that lets any nearby attacker remotely unlock, track, silence alarms, flash lights, or even disable a car’s ignition, prompting urgent patching efforts.

Black & White Path
Black & White Path
Black & White Path
Bluetooth Alarm Flaw Puts Millions of Cars at Risk of Remote Unlock and Disable

Modern cars increasingly function as mobile computers, and many dealers install third‑party aftermarket alarm systems such as KARR without owners’ knowledge. UCSD’s security team discovered that the KARR system, present in an estimated 2 + million U.S. vehicles, contains a critical Bluetooth flaw that allows any device within range to issue arbitrary commands.

Vulnerability Details

The flaw stems from a single, hard‑coded authentication key shared by all KARR units. Researchers reverse‑engineered the KARR mobile app, extracted the key, and built a custom Android application that can forge radio commands. These commands can unlock doors, sound the horn, flash lights, silence the alarm, or disable the ignition for up to ten minutes after the vehicle is turned off.

Impact Demonstrations

In a live demo for WIRED, the team used their app to unlock a car parked at a red light, disable its ignition, and trigger a “chaos” mode that simultaneously honked and flashed lights on multiple nearby vehicles. In a separate field test, scanning a campus parking lot for 20 minutes revealed 97 KARR‑equipped cars, illustrating the ease of locating vulnerable targets.

Research Methodology

Lead researcher Nishant Bhaskar first noticed the Bluetooth beacons while investigating credit‑card skimming devices at gas stations in 2018. By correlating the beacon prefixes with FCC records, he identified them as KARR alarms. Later, graduate student Jerry Yu reverse‑engineered the app, confirmed the universal key, and built the exploit.

To estimate deployment scale, the team leveraged the crowdsourced WiGLE database, which aggregates Bluetooth scans worldwide. Combining signal counts with serial‑number analysis, they estimated over two million active KARR devices across the United States.

Patch and Vendor Response

Acrisure, the company selling KARR, released a firmware update after an 18‑month delay following the initial vulnerability report. The update is delivered via the KARR mobile app; owners who have not installed the app receive no notification, leaving many unaware of the risk. Acrisure claims the real‑world risk is low, but the researchers demonstrated high‑impact attacks that could facilitate theft or sabotage.

Broader Implications

The universal key means any attacker can target any KARR‑equipped vehicle, regardless of ownership or whether the device was purchased as an optional feature. Because the device continues broadcasting Bluetooth signals even when the car is off (for up to ten minutes), it can be activated remotely and used for malicious purposes without the driver’s knowledge.

UCSD researchers urge owners to check for KARR markings on driver‑side windows, “SWDS” stickers, or a small flashing button beneath the dashboard, and to apply the firmware patch immediately.

KARR devices estimated in over 2 million cars require a patch
KARR devices estimated in over 2 million cars require a patch
Concept‑proof app showing attack menu and nearby vulnerable cars
Concept‑proof app showing attack menu and nearby vulnerable cars
WiGLE‑derived map of vulnerable vehicle distribution
WiGLE‑derived map of vulnerable vehicle distribution
Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

BluetoothAutomotive SecurityRemote ExploitKARRUCSDWiGLE
Black & White Path
Written by

Black & White Path

We are the beacon of the cyber world, a stepping stone on the road to security.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.