< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

3 clusters · 12 sources · 5 days · First seen · Last updated

Categories: TECHNOLOGY

KARR aftermarket security vulnerability

Entities: California · Yibo Wei · University of California, San Diego · KARR‑SWDS security system · Acrisure

Overview

University of California, San Diego researchers disclosed a Bluetooth flaw in the aftermarket KARR security system, installed by dealers in more than two million vehicles in the United States and Brazil. A single universal master key embedded in every module lets an attacker within Bluetooth range lock or unlock doors, sound the horn, flash lights and, in some cases, cut engine power.

The hardware is typically added by dealerships for inventory management and often remains active after owners decline the paid alarm service, meaning many drivers are unaware of its presence. Because KARR operates outside the vehicle’s native electronic architecture, conventional over‑the‑air updates or manufacturer recalls cannot reach it.

Acrisure Protection Group issued a firmware patch on 20 July 2025. Owners must locate the KARR module, install the update through the companion mobile app, and verify removal of the module’s indicator light or sticker. The patch does not enable remote starting and cannot control a vehicle while it is being driven.

Follow‑up research published in July 2026 reaffirmed that the shared authentication key still permits a single exploit across all units, affecting over two million cars—especially in Southern California—and a publicly accessible database now lists the affected VINs. A related SWDS anti‑theft device, built by Acrisure and using the same key, is estimated to be present in roughly 2.2 million vehicles purchased since 2017, with exposure spreading to other U.S. states and Japan through the secondary market. Removing the devices requires extensive hardware work, as the key cannot be changed or Bluetooth disabled remotely.

Security experts continue to advise motorists to check dashboards for the KARR badge, keep the mobile app up‑to‑date, and consider professional removal if the firmware update is insufficient.

Timeline

  1. 5 days ago

    [TECHNOLOGY] 5 sources
    Bluetooth flaw puts 2.2 million California cars at theft risk

    UC San Diego researchers found a Bluetooth security flaw in Acrisure anti‑theft devices that could let thieves control 2.2 million California‑based cars, with no easy fix.

  2. 7 days ago

    [TECHNOLOGY] 3 sources
    KARR Security System flaw puts over 2 million vehicles at risk

    A Bluetooth flaw in the KARR Security System could let attackers unlock, lock or immobilize over 2 million vehicles; a July 20 firmware update via a mobile app aims to patch the issue.

  3. 9 days ago

    [TECHNOLOGY] 3 sources
    KARR Bluetooth Flaw Threatens 2.2 Million US Vehicles

    A Bluetooth flaw in the aftermarket KARR system, affecting about 2.2 million U.S. cars, lets attackers remotely unlock or immobilize vehicles; a manual firmware patch is available but owners must update the app

Sources

brasilemfolhas.com.br · claimsjournal.com · infoguerra.com.br · malwarebytes.org · mezzogiornoitalia.it · motoryzacja.interia.pl · pentecostaltheology.org · poslovni.hr · sf-encyclopedia.com · southfloridareporter.com · techround.co.uk · thecyberexpress.com