Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
3 clusters · 12 sources · 5 days · First seen · Last updated
Categories: TECHNOLOGY
KARR aftermarket security vulnerability
Entities: California · Yibo Wei · University of California, San Diego · KARR‑SWDS security system · Acrisure
Overview
University of California, San Diego researchers disclosed a Bluetooth flaw in the aftermarket KARR security system, installed by dealers in more than two million vehicles in the United States and Brazil. A single universal master key embedded in every module lets an attacker within Bluetooth range lock or unlock doors, sound the horn, flash lights and, in some cases, cut engine power.
The hardware is typically added by dealerships for inventory management and often remains active after owners decline the paid alarm service, meaning many drivers are unaware of its presence. Because KARR operates outside the vehicle’s native electronic architecture, conventional over‑the‑air updates or manufacturer recalls cannot reach it.
Acrisure Protection Group issued a firmware patch on 20 July 2025. Owners must locate the KARR module, install the update through the companion mobile app, and verify removal of the module’s indicator light or sticker. The patch does not enable remote starting and cannot control a vehicle while it is being driven.
Follow‑up research published in July 2026 reaffirmed that the shared authentication key still permits a single exploit across all units, affecting over two million cars—especially in Southern California—and a publicly accessible database now lists the affected VINs. A related SWDS anti‑theft device, built by Acrisure and using the same key, is estimated to be present in roughly 2.2 million vehicles purchased since 2017, with exposure spreading to other U.S. states and Japan through the secondary market. Removing the devices requires extensive hardware work, as the key cannot be changed or Bluetooth disabled remotely.
Security experts continue to advise motorists to check dashboards for the KARR badge, keep the mobile app up‑to‑date, and consider professional removal if the firmware update is insufficient.
Timeline
-
5 days ago
[TECHNOLOGY] 5 sourcesBluetooth flaw puts 2.2 million California cars at theft riskUC San Diego researchers found a Bluetooth security flaw in Acrisure anti‑theft devices that could let thieves control 2.2 million California‑based cars, with no easy fix.
-
7 days ago
[TECHNOLOGY] 3 sourcesKARR Security System flaw puts over 2 million vehicles at riskA Bluetooth flaw in the KARR Security System could let attackers unlock, lock or immobilize over 2 million vehicles; a July 20 firmware update via a mobile app aims to patch the issue.
-
9 days ago
[TECHNOLOGY] 3 sourcesKARR Bluetooth Flaw Threatens 2.2 Million US VehiclesA Bluetooth flaw in the aftermarket KARR system, affecting about 2.2 million U.S. cars, lets attackers remotely unlock or immobilize vehicles; a manual firmware patch is available but owners must update the app
Sources
brasilemfolhas.com.br · claimsjournal.com · infoguerra.com.br · malwarebytes.org · mezzogiornoitalia.it · motoryzacja.interia.pl · pentecostaltheology.org · poslovni.hr · sf-encyclopedia.com · southfloridareporter.com · techround.co.uk · thecyberexpress.com