Bluetooth Alarm Flaw Puts Millions of Cars at Risk of Remote Unlock and Disable
UCSD researchers uncovered a Bluetooth‑based vulnerability in the aftermarket KARR alarm system—installed in over two million vehicles—that lets any nearby attacker remotely unlock, track, silence alarms, flash lights, or even disable a car’s ignition, prompting urgent patching efforts.
Modern cars increasingly function as mobile computers, and many dealers install third‑party aftermarket alarm systems such as KARR without owners’ knowledge. UCSD’s security team discovered that the KARR system, present in an estimated 2 + million U.S. vehicles, contains a critical Bluetooth flaw that allows any device within range to issue arbitrary commands.
Vulnerability Details
The flaw stems from a single, hard‑coded authentication key shared by all KARR units. Researchers reverse‑engineered the KARR mobile app, extracted the key, and built a custom Android application that can forge radio commands. These commands can unlock doors, sound the horn, flash lights, silence the alarm, or disable the ignition for up to ten minutes after the vehicle is turned off.
Impact Demonstrations
In a live demo for WIRED, the team used their app to unlock a car parked at a red light, disable its ignition, and trigger a “chaos” mode that simultaneously honked and flashed lights on multiple nearby vehicles. In a separate field test, scanning a campus parking lot for 20 minutes revealed 97 KARR‑equipped cars, illustrating the ease of locating vulnerable targets.
Research Methodology
Lead researcher Nishant Bhaskar first noticed the Bluetooth beacons while investigating credit‑card skimming devices at gas stations in 2018. By correlating the beacon prefixes with FCC records, he identified them as KARR alarms. Later, graduate student Jerry Yu reverse‑engineered the app, confirmed the universal key, and built the exploit.
To estimate deployment scale, the team leveraged the crowdsourced WiGLE database, which aggregates Bluetooth scans worldwide. Combining signal counts with serial‑number analysis, they estimated over two million active KARR devices across the United States.
Patch and Vendor Response
Acrisure, the company selling KARR, released a firmware update after an 18‑month delay following the initial vulnerability report. The update is delivered via the KARR mobile app; owners who have not installed the app receive no notification, leaving many unaware of the risk. Acrisure claims the real‑world risk is low, but the researchers demonstrated high‑impact attacks that could facilitate theft or sabotage.
Broader Implications
The universal key means any attacker can target any KARR‑equipped vehicle, regardless of ownership or whether the device was purchased as an optional feature. Because the device continues broadcasting Bluetooth signals even when the car is off (for up to ten minutes), it can be activated remotely and used for malicious purposes without the driver’s knowledge.
UCSD researchers urge owners to check for KARR markings on driver‑side windows, “SWDS” stickers, or a small flashing button beneath the dashboard, and to apply the firmware patch immediately.
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Black & White Path
We are the beacon of the cyber world, a stepping stone on the road to security.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
