Threat reportVulnerabilityTL-2026-1699

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

highPATCHED

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock (TL-2026-1699), also tracked as BLE Theft Auto, is a high-severity software vulnerability, first published 2026-07-25. It has no confirmed attribution, affects Acrisure Protection Group KARR / SWDS (SouthWest Dealer Services), maps to 18 MITRE ATT&CK techniques (T1005, T1036, T1040), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1699

Threat ID
TL-2026-1699
Also known as
BLE Theft Auto
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
automotive, consumer, transport
Target regions
united states of america, North America, canada, japan
Detection rules
9
Indicators of compromise
29

Malware and tooling in KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock

Malware and tooling: KARR Security PoC Android application, WiGLE

How KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock works

A single Bluetooth Low Energy (BLE) authentication key hardcoded in plaintext inside Acrisure Protection Group's KARR/SWDS aftermarket car alarm app is shared across every deployed unit, letting anyone within ~5 yards impersonate the legitimate app to unlock doors, sound horns/lights, and immobilize the engine on any of an estimated 2.2 million affected vehicles. UC San Diego researchers privately disclosed the flaw in January 2025; Acrisure shipped an opt-in firmware fix on July 20, 2026, roughly 18 months later, and the team is presenting the research ('BLE Theft Auto') at DEF CON and USENIX Security in August 2026.

KARR (also sold under the SWDS brand — SouthWest Dealer Services, an Acrisure Protection Group subsidiary that handles dealership installations) is a dealer-installed, subscription-based aftermarket vehicle security and remote-immobilizer system. The unit is mounted underneath the dashboard on the driver's side and communicates with an official companion smartphone app over Bluetooth Low Energy to arm/disarm the alarm, lock/unlock doors, sound the horn and lights, and remotely disable the ignition.

Researchers at UC San Diego's Department of Computer Science and Engineering — led by Professor Aaron Schulman with co-first authors Jerry Yu and Yibo Wei, building on Bluetooth-fingerprinting work by alumnus Nishant Bhaskar originating from a 2018 credit-card-skimmer detection project — reverse-engineered the official KARR mobile app and found that every KARR/SWDS unit shares one identical Bluetooth authentication key, stored in plaintext inside the app itself rather than being unique per device or per vehicle. Because the key cannot be changed or rotated, extracting it once from the app grants an attacker the ability to impersonate the legitimate app against any KARR/SWDS-equipped vehicle in Bluetooth range.

The researchers built a proof-of-concept Android application that replays the extracted key to send unauthorized BLE commands. From roughly five yards away, and without smashing a window or touching the vehicle, the PoC can unlock doors, disable the alarm, honk the horn, flash the lights, and — most seriously — prevent a parked vehicle's engine from starting, potentially stranding the driver. The attack executes silently: the vehicle emits only a brief beep and light flicker, and the owner receives no alert that a command was issued. In a live demonstration the team triggered horns and lights across multiple parked vehicles simultaneously ('mayhem mode'). The attack cannot start or drive a moving vehicle.

A compounding design flaw: dormant units — including the roughly one million owners who never opted into (or were unaware of) the paid subscription — still accept a single Bluetooth wake-up command that exposes the same command functionality, meaning an inactive/unsubscribed alarm is exploitable identically to an active one. Separately, KARR/SWDS units continue broadcasting an identifiable BLE signal while the vehicle is running and for up to 10 minutes after shutdown. Because these broadcasts are logged by crowdsourced wireless-signal databases such as WiGLE, an attacker can query a device's identifier over time to reconstruct a vehicle's parking/location history without ever approaching it, creating a stalking and surveillance risk independent of the unlock/immobilize attack.

Using WiGLE data and short field tests (97 active KARR units detected during a single 20-minute drive), the researchers estimate at least 2.2 million vehicles are affected nationwide (1.4 million confirmed), the large majority sold new by Honda, Toyota, Mazda, Ford, and Jeep dealerships across Southern California from 2017 to the present, with secondary distribution into Canada and Japan via the used-car resale market. A second aftermarket manufacturer, Rockledge, was evaluated in the same study; its devices require an attacker to intercept traffic during active use (a man-in-the-middle-style capture) rather than a one-time static key extraction, making it harder to exploit, but Rockledge did not respond to disclosure and the researchers could not fully validate its security.

UC San Diego privately disclosed the vulnerability to Acrisure in January 2025 and separately notified the National Highway Traffic Safety Administration given the vehicle-safety implications. Acrisure did not ship a firmware fix until July 20, 2026 — about 18 months later — and the fix is opt-in: owners must independently discover whether their vehicle has a KARR/SWDS unit (via driver-side window stickers or a small blinking-light module under the dash), install the KARR Security app even if they never subscribed, pair it to the vehicle, and manually apply the update. There is no over-the-air manufacturer recall path since the hardware is third-party/aftermarket, and physical removal requires dashboard disassembly (cutting and reconnecting wires). A KARR/Acrisure spokesperson characterized the flaw as 'highly complex' and 'low risk to customers under real-world conditions'; the lead researcher called it 'probably the worst' car-hacking issue publicly documented to date, noting the attack, once developed, is executable with standard consumer hardware. No CVE identifier has been publicly assigned to this issue. The researchers withheld precise reverse-engineering methodology to reduce replication risk and are presenting the peer-reviewed paper 'BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems' at DEF CON 34 (Aug 9, 2026, Las Vegas) and USENIX Security 2026 (Aug 12, 2026, Baltimore, MD); the work was supported by NSF grant CNS-2239163.

MITRE ATT&CK techniques used in TL-2026-1699

Collection

T1005 Data from Local System; T1119 Automated Collection

Defense Evasion

T1036 Masquerading

Credential Access

T1040 Network Sniffing; T1552 Unsecured Credentials

Discovery

T1046 Network Service Discovery; T1120 Peripheral Device Discovery

Command and Control

T1095 Non-Application Layer Protocol

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1529 System Shutdown/Reboot; T1657 Financial Theft

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1587 Develop Capabilities

Reconnaissance

T1591 Gather Victim Org Information; T1592 Gather Victim Host Information; T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock

  • Acrisure Protection Group — KARR / SWDS (SouthWest Dealer Services) Aftermarket Vehicle Security & Remote Immobilizer System (BLE-based)
    Vulnerable versions: All KARR/SWDS units manufactured and sold 2017-2026 running pre-July 20, 2026 firmware, including dormant/never-subscribed units
    Fixed in: Firmware update released July 20, 2026, applied via the KARR Security mobile app
  • Rockledge — Aftermarket BLE-based vehicle remote-control / anti-theft device
    Vulnerable versions: Unspecified — evaluated by researchers in the same study; requires interception of traffic during active use rather than one-time static key extraction, making it harder to exploit than KARR/SWDS, but not confirmed unaffected since Rockledge did not respond to disclosure
    Fixed in: Not disclosed in public reporting

Remediation for KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock

Patches

  • Acrisure Protection Group firmware update for KARR/SWDS units, released July 20, 2026, distributed exclusively through the KARR Security mobile app

Immediate actions

  • Check the driver-side window for a 'KARR' or 'SWDS' sticker and look underneath the dashboard for a small module with a blinking light to determine whether the vehicle has an affected unit installed
  • Download the official KARR Security mobile app and pair it with the vehicle even if a subscription was never purchased, then apply the July 20, 2026 firmware update immediately
  • If unsure whether a unit is installed, contact the selling dealership directly, since roughly half of owners are unaware a KARR/SWDS system exists on their vehicle

Workarounds

  • Request dealership or installer removal of the KARR/SWDS unit from the dashboard if the firmware update cannot or will not be applied
  • Minimize time parked in extended, unattended public locations where the ~5-yard BLE proximity attack and passive location-tracking risk are most exploitable

Longer-term hardening

  • Aftermarket BLE-based vehicle security vendors should move from a single shared authentication key embedded in the companion app to per-device, rotatable, uniquely provisioned keys
  • Firmware updates for safety-relevant aftermarket automotive hardware should be pushed automatically or through a mandatory channel rather than gated behind an opt-in subscription app
  • Regulators such as NHTSA should evaluate disclosure-to-patch service-level expectations for aftermarket automotive security devices given the roughly 18-month gap observed in this case
  • Reduce or randomize BLE advertisement persistence after vehicle shutdown to close the location-tracking and post-shutdown remote-activation window
  • Disable or gate the dormant-unit BLE wake-up command so unsubscribed/inactive alarms are not remotely exploitable

Weaknesses (CWE) in KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock

CWE-798, CWE-321, CWE-294, CWE-522

Timeline of KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock

  • UC San Diego PhD student Nishant Bhaskar first identifies persistent Bluetooth device fingerprints from KARR-branded hardware while researching credit-card-skimmer detection, seeding the later BLE Theft Auto investigation.
  • UC San Diego researchers privately disclose the shared, hardcoded BLE authentication key vulnerability in KARR/SWDS devices to manufacturer Acrisure Protection Group.
  • Researchers validate the scale of exposure using WiGLE wireless-signal data and short field drives, including detecting 97 actively broadcasting KARR units during a single 20-minute Southern California test.
  • Acrisure Protection Group releases a firmware update for KARR/SWDS devices, distributed exclusively through the KARR Security mobile app, roughly 18 months after private disclosure.
  • Researchers notify the National Highway Traffic Safety Administration of the vulnerability given its vehicle-safety implications.
  • AppleInsider and The Drive publish early coverage of the newly available KARR firmware patch and the underlying Bluetooth vulnerability.
  • GBHackers, Cybersecurity News, CyberPress, TheCyberExpress, Popular Science, SC Media, and Jalopnik publish detailed technical coverage of the KARR/SWDS Bluetooth vulnerability.
  • Malwarebytes publishes follow-on analysis detailing the dormant-unit BLE wake-up command, silent no-owner-alert command execution, and the Rockledge comparison.
  • Researchers are scheduled to present the 'BLE Theft Auto' findings at DEF CON 34 in Las Vegas.
  • Researchers are scheduled to present the peer-reviewed paper 'BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems' at the USENIX Security Symposium in Baltimore, MD.

Sources cited for KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock

Detection coverage for TL-2026-1699

As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1699 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats