Millions of California-bought cars vulnerable to Bluetooth hijacking
Researchers from UC San Diego have identified a significant security flaw in aftermarket KARR and SWDS systems that could allow attackers to unlock vehicles via Bluetooth.
By The Register
At least 2.2 million vehicles equipped with dealer-installed KARR and SWDS security systems are susceptible to Bluetooth attacks, according to researchers at the University of California San Diego (UCSD). The vulnerability allows an attacker within Bluetooth range to unlock doors and, in some cases, prevent a stopped vehicle from starting.
The research indicates that all KARR and SWDS devices manufactured by Acrisure rely on the same secure key, which poses a serious security risk. Jerry Yu, a co-author of the study, explained that this flaw means that anyone with knowledge of the key and a Bluetooth-enabled device can unlock a vehicle from as close as five yards away.
KARR and SWDS systems are typically installed by dealerships and are marketed as both a key fob replacement and an anti-theft device. They enable tracking of vehicles in the event of theft. However, UCSD researchers noted that these devices remain active even if the vehicle owner opts out of the service, leaving many vehicles at risk.
Yibo Wei, another co-author and PhD candidate at UCSD, highlighted the difficulty of removing these devices, stating that it involves opening the dashboard and manipulating wires connected to the car's computer and ignition system.
The majority of the vulnerable vehicles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California between 2017 and 2026. However, due to secondary market resales, affected vehicles may be found across the United States and even in Japan.
In response to the vulnerability, Acrisure released a firmware update on July 20, 2026, which can be installed by both active and inactive customers through the KARR app. The company has not confirmed whether it is actively notifying customers about the need to update their systems.
A KARR spokesperson stated that the vulnerability is complex and presents a low risk to customers under real-world conditions, despite the findings from UCSD. They also claimed that only a small percentage of devices with specific Bluetooth components are affected.
The vulnerability was discovered by UCSD researchers during a separate investigation into credit card skimmers, where they encountered unidentified Bluetooth fingerprints. The team will present their findings at DEF CON on August 9 and at the USENIX Security conference on August 12.