KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization — Threadlinqs Intelligence
As of 2026-07-25, KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 28 indicators of compromise.
Threat ID: TL-2026-1701 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
A single hardcoded/shared Bluetooth authentication key embedded across every KARR-SWDS aftermarket vehicle alarm (Acrisure Protection Group) lets anyone within roughly five yards impersonate the
KARR-SWDS is a Bluetooth Low Energy (BLE) aftermarket vehicle security/immobilizer system manufactured by Acrisure Protection Group and commonly installed by dealerships (Honda, Toyota, Mazda, Ford, and Jeep lots identified in Southern California, 2017-2026) as loss-prevention/anti-theft inventory protection before sale. Researchers at the University of California, San Diego (Aaron Schulman's group, Department of Computer Science and Engineering) discovered the flaw when then-PhD student Nishant Bhaskar first noticed unrecognized Bluetooth fingerprints while investigating unrelated credit-card-skimmer research in 2018, later tracing the signatures to Acrisure and Rockledge hardware. By reverse-engineering the official KARR Security mobile app, the team -- co-first-authors Jerry Yu and Yibo Wei, with co-authors Sumanth Rao, Mohak Vaswani, Jefferson Chien, and UC San Diego Health's Christian Dameff, under senior author Aaron Schulman -- extracted a single BLE authentication key that is shared, unmodified, across every deployed KARR-SWDS device -- functionally equivalent to every unit shipping with the same hardcoded password. Once cracked, that one key grants an attacker impersonation capability against the entire installed base with no device-specific exploitation required, and researchers noted the attack "becomes straightforward once the key is known, making the technique scalable across all affected systems." The research was partially funded by National Science Foundation grant CNS-2239163.
Using a proof-of-concept Android application (not publicly released, to limit replication by thieves), researchers demonstrated unauthorized command injection over BLE from as close as roughly five yards: locking/unlocking doors, disabling the alarm, triggering the horn and headlights, and immobilizing/preventing engine start while parked (the flaw cannot start or drive a moving vehicle). Devices continue to broadcast BLE beacons while the engine is running and for up to ten minutes after shutdown, extending the practical attack window. The researchers characterized a compounding real-world theft chain: an attacker uses the Bluetooth flaw to unlock the vehicle silently (no window smash, no forced-lock alarm trigger), then uses commercially available locksmith key-cloning tools to clone an ignition key from the vehicle's own computer -- enabling theft without ever triggering the alarm the device was sold to provide. UCSD professor Stefan Savage described the issue as "probably the worst" car-hacking vulnerability he has encountered.
A second, independently concerning finding is passive location tracking: KARR-SWDS devices continuously broadcast a stable BLE identifier that is picked up and logged by crowdsourced wardriving databases such as WiGLE. Feeding a device's identifier into WiGLE lets an attacker reconstruct a vehicle's historical parking locations -- one outlet called it "a stalker's dream" -- and researchers and outlets characterized this as a stalking-enabling capability that is, in some respects, more concerning than the unlock flaw itself. Researchers used the same WiGLE data to estimate device population, initially counting 1.4 million vulnerable vehicles and refining the estimate to at least 2.2 million after further analysis that accounted for secondhand-market resale distribution across the United States, Canada, and Japan; a field test found 97 vulnerable vehicles within a 20-minute drive of the UCSD campus.
A related aftermarket vendor, Rockledge, ships BLE remote-control alarm/immobilizer hardware that researchers found may also be vulnerable, but via a higher-complexity capture-replay attack: rather than a single static universal key, an attacker must be physically present to intercept and record a legitimate owner's BLE pairing/command exchange, then replay it later to gain access. Rockledge's exposure remained unvalidated by researchers at time of publication.
Researchers privately disclosed the vulnerabilities
Weaknesses (CWE)
CWE-798, CWE-321, CWE-294, CWE-287
Target sectors: automotive, consumer, retail
Target regions: North America, united states of america, canada, japan
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 28 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, T1595.002, T1596.005, T1592.001, T1592.004, T1587.001, T1588.002, T1059, T1005, T1119, T1213