# KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

> A single Bluetooth Low Energy (BLE) authentication key hardcoded in plaintext inside Acrisure Protection Group's KARR/SWDS aftermarket car alarm app is shared across every deployed unit, letting anyone within ~5 yards impersonate the legitimate app to unlock doors, sound horns/lights, and immobilize the engine on any of an estimated 2.2 million affected vehicles. UC San Diego researchers privately disclosed the flaw in January 2025; Acrisure shipped an opt-in firmware fix on July 20, 2026, roughly 18 months later, and the team is presenting the research ('BLE Theft Auto') at DEF CON and USENIX Security in August 2026.

- **Published:** 2026-07-25T00:00:00Z
- **Last reviewed:** 2026-07-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1699
- **ID:** TL-2026-1699
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)

## Description

KARR (also sold under the SWDS brand — SouthWest Dealer Services, an Acrisure Protection Group subsidiary that handles dealership installations) is a dealer-installed, subscription-based aftermarket vehicle security and remote-immobilizer system. The unit is mounted underneath the dashboard on the driver's side and communicates with an official companion smartphone app over Bluetooth Low Energy to arm/disarm the alarm, lock/unlock doors, sound the horn and lights, and remotely disable the ignition.

Researchers at UC San Diego's Department of Computer Science and Engineering — led by Professor Aaron Schulman with co-first authors Jerry Yu and Yibo Wei, building on Bluetooth-fingerprinting work by alumnus Nishant Bhaskar originating from a 2018 credit-card-skimmer detection project — reverse-engineered the official KARR mobile app and found that every KARR/SWDS unit shares one identical Bluetooth authentication key, stored in plaintext inside the app itself rather than being unique per device or per vehicle. Because the key cannot be changed or rotated, extracting it once from the app grants an attacker the ability to impersonate the legitimate app against any KARR/SWDS-equipped vehicle in Bluetooth range.

The researchers built a proof-of-concept Android application that replays the extracted key to send unauthorized BLE commands. From roughly five yards away, and without smashing a window or touching the vehicle, the PoC can unlock doors, disable the alarm, honk the horn, flash the lights, and — most seriously — prevent a parked vehicle's engine from starting, potentially stranding the driver. The attack executes silently: the vehicle emits only a brief beep and light flicker, and the owner receives no alert that a command was issued. In a live demonstration the team triggered horns and lights across multiple parked vehicles simultaneously ('mayhem mode'). The attack cannot start or drive a moving vehicle.

A compounding design flaw: dormant units — including the roughly one million owners who never opted into (or were unaware of) the paid subscription — still accept a single Bluetooth wake-up command that exposes the same command functionality, meaning an inactive/unsubscribed alarm is exploitable identically to an active one. Separately, KARR/SWDS units continue broadcasting an identifiable BLE signal while the vehicle is running and for up to 10 minutes after shutdown. Because these broadcasts are logged by crowdsourced wireless-signal databases such as WiGLE, an attacker can query a device's identifier over time to reconstruct a vehicle's parking/location history without ever approaching it, creating a stalking and surveillance risk independent of the unlock/immobilize attack.

Using WiGLE data and short field tests (97 active KARR units detected during a single 20-minute drive), the researchers estimate at least 2.2 million vehicles are affected nationwide (1.4 million confirmed), the large majority sold new by Honda, Toyota, Mazda, Ford, and Jeep dealerships across Southern California from 2017 to the present, with secondary distribution into Canada and Japan via the used-car resale market. A second aftermarket manufacturer, Rockledge, was evaluated in the same study; its devices require an attacker to intercept traffic during active use (a man-in-the-middle-style capture) rather than a one-time static key extraction, making it harder to exploit, but Rockledge did not respond to disclosure and the researchers could not fully validate its security.

UC San Diego privately disclosed the vulnerability to Acrisure in January 2025 and separately notified the National Highway Traffic Safety Administration given the vehicle-safety implications. Acrisure did not ship a firmware fix until July 20, 2026 — about 18 months later — and the fix is opt-in: owners must independently discover whether their vehicle has a KARR/SWDS unit (via driver-side window stickers or a small blinking-light module under the dash), install the KARR Security app even if they never subscribed, pair it to the vehicle, and manually apply the update. There is no over-the-air manufacturer recall path since the hardware is third-party/aftermarket, and physical removal requires dashboard disassembly (cutting and reconnecting wires). A KARR/Acrisure spokesperson characterized the flaw as 'highly complex' and 'low risk to customers under real-world conditions'; the lead researcher called it 'probably the worst' car-hacking issue publicly documented to date, noting the attack, once developed, is executable with standard consumer hardware. No CVE identifier has been publicly assigned to this issue. The researchers withheld precise reverse-engineering methodology to reduce replication risk and are presenting the peer-reviewed paper 'BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems' at DEF CON 34 (Aug 9, 2026, Las Vegas) and USENIX Security 2026 (Aug 12, 2026, Baltimore, MD); the work was supported by NSF grant CNS-2239163.

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1591 Gather Victim Org Information
- T1596 Search Open Technical Databases
- T1587 Develop Capabilities
- T1190 Exploit Public-Facing Application
- T1120 Peripheral Device Discovery
- T1046 Network Service Discovery
- T1552 Unsecured Credentials
- T1040 Network Sniffing
- T1005 Data from Local System
- T1119 Automated Collection
- T1095 Non-Application Layer Protocol
- T1210 Exploitation of Remote Services
- T1036 Masquerading
- T1567 Exfiltration Over Web Service
- T1529 System Shutdown/Reboot
- T1657 Financial Theft

## Sources

- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://gbhackers.com/karr-bluetooth-vulnerability/)
- [2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft](https://today.ucsd.edu/story/2-million-cars-with-anti-theft-systems-installed-by-dealers-are-at-higher-risk-of-theft)
- [2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft](https://www.eurekalert.org/news-releases/1136978)
- [KARR Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks](https://cybersecuritynews.com/karr-bluetooth-vulnerability-exposes/)
- [Millions of cars could be tracked and unlocked by a hidden security flaw](https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw)
- [Anyone in Bluetooth Range Can Unlock Cars, Kill Engines Through Alarms Owners May Never Have Paid For](https://www.thedrive.com/news/anyone-in-bluetooth-range-can-unlock-cars-kill-engines-through-alarms-owners-may-never-have-paid-for)
- [KARR Car Alarm Flaw Lets Nearby Attackers Unlock and Immobilize Vehicles](https://cyberpress.org/karr-car-alarm-flaw/)
- [If you've got this dealer-installed car alarm, patch it today with your iPhone](https://appleinsider.com/articles/26/07/22/if-youve-got-this-dealer-installed-car-alarm-patch-it-today-with-your-iphone)
- [KARR Security System Flaw: Update KARR Alarm With iPhone](https://thecyberexpress.com/karr-security-system-flaw/)
- [2 million cars at risk of sneaky Bluetooth hack that unlocks doors](https://www.popsci.com/technology/car-bluetooth-cybersecurity-hack/)
- [Aftermarket Anti-Theft Device Owners Don't Know How Vulnerable They Are To Hacking](https://www.jalopnik.com/2220373/aftermarket-anti-theft-device-leaves-owners-vunerable-to-hacking/)
- [Millions of vehicles vulnerable to Bluetooth car theft attacks](https://www.scworld.com/brief/millions-of-vehicles-vulnerable-to-bluetooth-car-theft-attacks)
- [KARR Security — Official Site (patch download / device info)](https://www.karrsecurity.com/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1699
