KARR Bluetooth Flaw Threatens 2.2 Million US Vehicles
Researchers at the University of California, San Diego have identified a Bluetooth vulnerability in the aftermarket KARR security system that is installed in an estimated 2.2 million vehicles across the United States. The flaw stems from a single universal master key embedded in all KARR devices, allowing an attacker within Bluetooth range to issue commands that can unlock doors, sound horns, flash lights and, more critically, cut engine power to immobilize a moving car.
The hardware is typically installed by dealerships to manage inventory and often remains in the vehicle even after owners decline the service, meaning many drivers are unaware of its presence. Because KARR is not part of the vehicle’s native electronic architecture, traditional over‑the‑air updates or manufacturer recalls are ineffective. Acrisure Protection Group released a firmware patch on July 20, 2025, but owners must manually check for the KARR module and apply the update through the companion mobile app.
Security experts advise motorists to inspect the dashboard area for the KARR indicator light or sticker and to ensure the app is up‑to‑date to close the Bluetooth loophole.