Bluetooth flaw puts 2.2 million California cars at theft risk
Researchers at the University of California, San Diego have identified a security flaw in Acrisure‑built KARR and SWDS anti‑theft devices that were installed by dealers in California. The devices, which rely on a single secure key, can be accessed over Bluetooth, allowing an attacker to unlock doors, sound the horn, flash headlights and even prevent the engine from starting. The vulnerability affects roughly 2.2 million vehicles purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships since 2017, and may have spread through the secondary market to other U.S. states and Japan. A publicly accessible database contains information on all cars equipped with the system. “Removing the devices is not trivial,” said UC San Diego PhD candidate Yibo Wei, noting that fixing the issue requires extensive hardware work, as changing the key or disabling Bluetooth is not feasible.
Entities: Acrisure · California · KARR‑SWDS security system · University of California, San Diego · Yibo Wei