Threat reportVulnerabilityTL-2026-1701

KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization

highACTIVE

KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M (TL-2026-1701), also tracked as KARR-SWDS Bluetooth Universal Key Flaw, is a high-severity software vulnerability, first published 2026-07-25. It has no confirmed attribution, affects Acrisure Protection Group KARR-SWDS aftermarket Bluetooth vehicle, maps to 19 MITRE ATT&CK techniques (T1005, T1046, T1059), and is covered by 9 detection rules and 28 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
28Indicators of compromise

Key facts for TL-2026-1701

Threat ID
TL-2026-1701
Also known as
KARR-SWDS Bluetooth Universal Key Flaw, BLE Theft Auto
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
automotive, consumer, retail
Target regions
North America, united states of america, canada, japan
Detection rules
9
Indicators of compromise
28

Malware and tooling in KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M

Malware and tooling: KARR Security app (iOS / Android), Locksmith key-cloning tools (commercial, generic), UCSD proof-of-concept Android impersonation app (unreleased), WiGLE (Wireless Geographic Logging Engine)

How KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M works

A single hardcoded/shared Bluetooth authentication key embedded across every KARR-SWDS aftermarket vehicle alarm (Acrisure Protection Group) lets anyone within roughly five yards impersonate the owner's app to unlock doors, disable the alarm, sound the horn/lights, and immobilize a parked engine; UC San Diego researchers extracted the universal key by reverse-engineering the KARR mobile app and built a working proof-of-concept Android tool, with an estimated 2.2 million dealer-installed units (2017-2026, including secondhand-market resale into Canada and Japan) affected and a related but harder-to-exploit capture-replay flaw in competing Rockledge systems. Acrisure shipped a firmware patch on 2026-07-20, but it requires manual, per-vehicle application via the KARR Security app, and roughly half of affected owners never activated/paid for the service and may not know the hardware — or the app needed to patch it — exists, leaving an estimated ~1 million vehicles perpetually unpatched.

KARR-SWDS is a Bluetooth Low Energy (BLE) aftermarket vehicle security/immobilizer system manufactured by Acrisure Protection Group and commonly installed by dealerships (Honda, Toyota, Mazda, Ford, and Jeep lots identified in Southern California, 2017-2026) as loss-prevention/anti-theft inventory protection before sale. Researchers at the University of California, San Diego (Aaron Schulman's group, Department of Computer Science and Engineering) discovered the flaw when then-PhD student Nishant Bhaskar first noticed unrecognized Bluetooth fingerprints while investigating unrelated credit-card-skimmer research in 2018, later tracing the signatures to Acrisure and Rockledge hardware. By reverse-engineering the official KARR Security mobile app, the team -- co-first-authors Jerry Yu and Yibo Wei, with co-authors Sumanth Rao, Mohak Vaswani, Jefferson Chien, and UC San Diego Health's Christian Dameff, under senior author Aaron Schulman -- extracted a single BLE authentication key that is shared, unmodified, across every deployed KARR-SWDS device -- functionally equivalent to every unit shipping with the same hardcoded password. Once cracked, that one key grants an attacker impersonation capability against the entire installed base with no device-specific exploitation required, and researchers noted the attack "becomes straightforward once the key is known, making the technique scalable across all affected systems." The research was partially funded by National Science Foundation grant CNS-2239163.

Using a proof-of-concept Android application (not publicly released, to limit replication by thieves), researchers demonstrated unauthorized command injection over BLE from as close as roughly five yards: locking/unlocking doors, disabling the alarm, triggering the horn and headlights, and immobilizing/preventing engine start while parked (the flaw cannot start or drive a moving vehicle). Devices continue to broadcast BLE beacons while the engine is running and for up to ten minutes after shutdown, extending the practical attack window. The researchers characterized a compounding real-world theft chain: an attacker uses the Bluetooth flaw to unlock the vehicle silently (no window smash, no forced-lock alarm trigger), then uses commercially available locksmith key-cloning tools to clone an ignition key from the vehicle's own computer -- enabling theft without ever triggering the alarm the device was sold to provide. UCSD professor Stefan Savage described the issue as "probably the worst" car-hacking vulnerability he has encountered.

A second, independently concerning finding is passive location tracking: KARR-SWDS devices continuously broadcast a stable BLE identifier that is picked up and logged by crowdsourced wardriving databases such as WiGLE. Feeding a device's identifier into WiGLE lets an attacker reconstruct a vehicle's historical parking locations -- one outlet called it "a stalker's dream" -- and researchers and outlets characterized this as a stalking-enabling capability that is, in some respects, more concerning than the unlock flaw itself. Researchers used the same WiGLE data to estimate device population, initially counting 1.4 million vulnerable vehicles and refining the estimate to at least 2.2 million after further analysis that accounted for secondhand-market resale distribution across the United States, Canada, and Japan; a field test found 97 vulnerable vehicles within a 20-minute drive of the UCSD campus.

A related aftermarket vendor, Rockledge, ships BLE remote-control alarm/immobilizer hardware that researchers found may also be vulnerable, but via a higher-complexity capture-replay attack: rather than a single static universal key, an attacker must be physically present to intercept and record a legitimate owner's BLE pairing/command exchange, then replay it later to gain access. Rockledge's exposure remained unvalidated by researchers at time of publication.

Researchers privately disclosed the vulnerabilities to Acrisure and to the National Highway Traffic Safety Administration (NHTSA) in January 2025. Acrisure Protection Group released a firmware patch on 2026-07-20 -- roughly 18 months after disclosure, a delay coverage explicitly contrasted with Subaru's reported 24-hour turnaround on an unrelated vulnerability -- but public statements from the company described the research as "highly complex" and presenting "low risk to customers under real-world conditions," a characterization multiple outlets noted conflicts directly with the researchers' own "straightforward" and "scalable" assessment. The fix is not delivered automatically: owners must download the KARR Security app (iOS or Android, open to any user regardless of subscription status), pair it with the vehicle's KARR/SWDS hardware (identifiable via a driver-side window sticker or a small blinking-light button under the dashboard), enter the last eight digits of the VIN, and manually trigger "Customer Service > Firmware Update." Because the KARR-SWDS ecosystem sits outside automaker OTA update channels, there is no centralized push-patch mechanism, and researchers estimate roughly half of affected owners never activated or paid for the alarm service and are unaware the hardware -- or the need to patch it -- exists, leaving an estimated ~1 million of the 2.2 million-unit fleet perpetually unpatched. The research, titled "BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems," is scheduled for coordinated public presentation at DEF CON 34 (2026-08-09, Las Vegas) and the USENIX Security Symposium (2026-08-12, Baltimore). No CVE has been assigned to this issue as of publication.

MITRE ATT&CK techniques used in TL-2026-1701

Collection

T1005 Data from Local System; T1119 Automated Collection; T1213 Data from Information Repositories

Discovery

T1046 Network Service Discovery; T1120 Peripheral Device Discovery

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1199 Trusted Relationship

Impact

T1489 Service Stop; T1657 Financial Theft

lateral-movement

T1550 Use Alternate Authentication Material

Credential Access

T1552.001 Credentials In Files

Resource Development

T1587.001 Malware; T1588.002 Tool

Reconnaissance

T1592.001 Hardware; T1592.004 Client Configurations; T1595.002 Vulnerability Scanning; T1596.005 Scan Databases

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M

  • Acrisure Protection Group — KARR-SWDS aftermarket Bluetooth vehicle alarm / immobilizer system
    Vulnerable versions: All KARR-SWDS firmware deployed prior to the 2026-07-20 update, dealer-installed 2017-2026
    Fixed in: Firmware released 2026-07-20, applied manually via the KARR Security app (iOS/Android)
  • Rockledge — Rockledge aftermarket BLE vehicle remote-control / alarm system
    Vulnerable versions: Systems susceptible to capture-replay of the BLE pairing/command exchange (higher attack complexity than KARR-SWDS; requires attacker presence during legitimate owner use)
    Fixed in: Not confirmed publicly at time of publication

Remediation for KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M

Patches

  • Acrisure Protection Group firmware update, released 2026-07-20, delivered over Bluetooth via the KARR Security companion app.

Immediate actions

  • Download the official KARR Security app (iOS App Store or Google Play), connect it to the vehicle's KARR-SWDS hardware over Bluetooth, and apply the 2026-07-20 firmware update via Customer Service > Firmware Update, entering the last eight digits of the VIN.
  • Visually inspect vehicles bought new or used from 2017-2026 for KARR/SWDS branding -- a driver-side window sticker or a small button with a blinking light under the dashboard -- even if the alarm subscription was never activated or paid for.
  • Dealers that installed KARR-SWDS hardware between 2017 and 2026 (identified brands: Honda, Toyota, Mazda, Ford, Jeep) should proactively audit lot and previously-sold inventory and notify owners, including the roughly 50% who never activated or paid for the service and may not know the device -- or the patch app -- exists.

Workarounds

  • Where the firmware update cannot yet be applied, request dealer removal or physical disabling of the KARR-SWDS module.
  • Park in monitored or enclosed locations to reduce exposure to both the ~5-yard Bluetooth command-injection range and BLE-fingerprint-based location tracking via public wardriving databases.

Longer-term hardening

  • Acrisure and Rockledge should replace the single shared/hardcoded BLE authentication key with per-device unique keys and proper key-provisioning/rotation.
  • Reduce or disable BLE advertising while the vehicle is off (current devices broadcast for up to 10 minutes post-shutdown) and stop broadcasting a static, trackable identifier that can be correlated via public wardriving databases like WiGLE.
  • Build an automatic/OTA patch-delivery path for aftermarket dealer-installed hardware instead of relying on manual, per-vehicle owner action through a companion app.
  • NHTSA and dealer networks should coordinate mandatory, recall-style notification for safety- and theft-relevant aftermarket security hardware, independent of whether the buyer activated or paid for the service, including secondhand-market buyers outside the original point of sale (Canada, Japan).

Weaknesses (CWE) in KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M

CWE-798, CWE-321, CWE-294, CWE-287

Timeline of KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M

  • KARR-SWDS dealer-installed BLE alarm hardware begins widespread deployment across Southern California Honda, Toyota, Mazda, Ford, and Jeep dealership lots, continuing through 2026.
  • UC San Diego then-PhD student Nishant Bhaskar first notices unrecognized Bluetooth fingerprints while investigating credit-card skimmers, later tracing the signatures to Acrisure and Rockledge aftermarket alarm devices.
  • UC San Diego researchers privately disclose the universal shared-key vulnerability to Acrisure Protection Group and notify the National Highway Traffic Safety Administration (NHTSA).
  • Acrisure Protection Group releases a firmware update addressing the shared-key flaw, deliverable only via manual pairing with the KARR Security mobile app, roughly 18 months after disclosure -- a delay coverage contrasts with Subaru's reported 24-hour turnaround on an unrelated vulnerability.
  • AppleInsider publishes consumer patch guidance detailing how to identify KARR-SWDS hardware and apply the firmware update via the iOS/Android KARR Security app.
  • Cyber Security News publishes the first widely syndicated report of the vulnerability, followed within hours by GBHackers, CyberPress, The Cyber Express, The Drive, and PopSci.
  • Malwarebytes Labs publishes analysis highlighting that KARR-SWDS devices' persistent BLE broadcast can be correlated via crowdsourced wardriving databases (WiGLE) to reconstruct a vehicle's parking-location history, a stalking-enabling risk described as "a stalker's dream" and distinct from the unlock flaw.
  • UC San Diego researchers are scheduled to present the "BLE Theft Auto" findings publicly at DEF CON 34 in Las Vegas.
  • The peer-reviewed "BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems" paper is scheduled for presentation at the USENIX Security Symposium in Baltimore.

Sources cited for KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M

Detection coverage for TL-2026-1701

As of 2026-07-25, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1701 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
28 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats