KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars — Threadlinqs Intelligence
As of 2026-07-25, KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1699 · Severity: HIGH · Status: PATCHED · Category: VULNERABILITY
A single Bluetooth Low Energy (BLE) authentication key hardcoded in plaintext inside Acrisure Protection Group's KARR/SWDS aftermarket car alarm app is shared across every deployed unit, letting
KARR (also sold under the SWDS brand — SouthWest Dealer Services, an Acrisure Protection Group subsidiary that handles dealership installations) is a dealer-installed, subscription-based aftermarket vehicle security and remote-immobilizer system. The unit is mounted underneath the dashboard on the driver's side and communicates with an official companion smartphone app over Bluetooth Low Energy to arm/disarm the alarm, lock/unlock doors, sound the horn and lights, and remotely disable the ignition.
Researchers at UC San Diego's Department of Computer Science and Engineering — led by Professor Aaron Schulman with co-first authors Jerry Yu and Yibo Wei, building on Bluetooth-fingerprinting work by alumnus Nishant Bhaskar originating from a 2018 credit-card-skimmer detection project — reverse-engineered the official KARR mobile app and found that every KARR/SWDS unit shares one identical Bluetooth authentication key, stored in plaintext inside the app itself rather than being unique per device or per vehicle. Because the key cannot be changed or rotated, extracting it once from the app grants an attacker the ability to impersonate the legitimate app against any KARR/SWDS-equipped vehicle in Bluetooth range.
The researchers built a proof-of-concept Android application that replays the extracted key to send unauthorized BLE commands. From roughly five yards away, and without smashing a window or touching the vehicle, the PoC can unlock doors, disable the alarm, honk the horn, flash the lights, and — most seriously — prevent a parked vehicle's engine from starting, potentially stranding the driver. The attack executes silently: the vehicle emits only a brief beep and light flicker, and the owner receives no alert that a command was issued. In a live demonstration the team triggered horns and lights across multiple parked vehicles simultaneously ('mayhem mode'). The attack cannot start or drive a moving vehicle.
A compounding design flaw: dormant units — including the roughly one million owners who never opted into (or were unaware of) the paid subscription — still accept a single Bluetooth wake-up command that exposes the same command functionality, meaning an inactive/unsubscribed alarm is exploitable identically to an active one. Separately, KARR/SWDS units continue broadcasting an identifiable BLE signal while the vehicle is running and for up to 10 minutes after shutdown. Because these broadcasts are logged by crowdsourced wireless-signal databases such as WiGLE, an attacker can query a device's identifier over time to reconstruct a vehicle's parking/location history without ever approaching it, creating a stalking and surveillance risk independent of the unlock/immobilize attack.
Using WiGLE data and short field tests (97 active KARR units detected during a single 20-minute drive), the researchers estimate at least 2.2 million vehicles are affected nationwide (1.4 million confirmed), the large majority sold new by Honda, Toyota, Mazda, Ford, and Jeep dealerships across Southern California from 2017 to the present, with secondary distribution into Canada and Japan via the used-car resale market. A second aftermarket manufacturer, Rockledge, was evaluated in the same study; its devices require an attacker to intercept traffic during active use (a man-in-the-middle-style capture) rather than a one-time static key extraction, making it harder to exploit, but Rockledge did not respond to disclosure and the researchers could not fully validate its security.
UC San Diego privately disclosed the vulnerability to Acrisure in January 2025 and separately notified the National Highway Traffic Safety Administration given the vehicle-safety implications. Acrisure did not ship a firmware fix until July 20, 2026 — about 18 months later — and the fix is opt-in: owners must independently discover whether their vehicle has a KARR/SWDS unit (via driver-side window stickers or a small blinking-light module under the dash), install the KARR Sec
Weaknesses (CWE)
CWE-798, CWE-321, CWE-294, CWE-522
Target sectors: automotive, consumer, transport
Target regions: united states of america, North America, canada, japan
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1595, T1592, T1591, T1596, T1587, T1587, T1190, T1120, T1046, T1552