# KARR Aftermarket Car Alarm Bluetooth Flaw Exposes 2.2M Vehicles to Remote Unlock and Immobilization

> A single hardcoded/shared Bluetooth authentication key embedded across every KARR-SWDS aftermarket vehicle alarm (Acrisure Protection Group) lets anyone within roughly five yards impersonate the owner's app to unlock doors, disable the alarm, sound the horn/lights, and immobilize a parked engine; UC San Diego researchers extracted the universal key by reverse-engineering the KARR mobile app and built a working proof-of-concept Android tool, with an estimated 2.2 million dealer-installed units (2017-2026, including secondhand-market resale into Canada and Japan) affected and a related but harder-to-exploit capture-replay flaw in competing Rockledge systems. Acrisure shipped a firmware patch on 2026-07-20, but it requires manual, per-vehicle application via the KARR Security app, and roughly half of affected owners never activated/paid for the service and may not know the hardware — or the app needed to patch it — exists, leaving an estimated ~1 million vehicles perpetually unpatched.

- **Published:** 2026-07-25T00:00:00Z
- **Last reviewed:** 2026-07-25T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1701
- **ID:** TL-2026-1701
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

KARR-SWDS is a Bluetooth Low Energy (BLE) aftermarket vehicle security/immobilizer system manufactured by Acrisure Protection Group and commonly installed by dealerships (Honda, Toyota, Mazda, Ford, and Jeep lots identified in Southern California, 2017-2026) as loss-prevention/anti-theft inventory protection before sale. Researchers at the University of California, San Diego (Aaron Schulman's group, Department of Computer Science and Engineering) discovered the flaw when then-PhD student Nishant Bhaskar first noticed unrecognized Bluetooth fingerprints while investigating unrelated credit-card-skimmer research in 2018, later tracing the signatures to Acrisure and Rockledge hardware. By reverse-engineering the official KARR Security mobile app, the team -- co-first-authors Jerry Yu and Yibo Wei, with co-authors Sumanth Rao, Mohak Vaswani, Jefferson Chien, and UC San Diego Health's Christian Dameff, under senior author Aaron Schulman -- extracted a single BLE authentication key that is shared, unmodified, across every deployed KARR-SWDS device -- functionally equivalent to every unit shipping with the same hardcoded password. Once cracked, that one key grants an attacker impersonation capability against the entire installed base with no device-specific exploitation required, and researchers noted the attack "becomes straightforward once the key is known, making the technique scalable across all affected systems." The research was partially funded by National Science Foundation grant CNS-2239163.

Using a proof-of-concept Android application (not publicly released, to limit replication by thieves), researchers demonstrated unauthorized command injection over BLE from as close as roughly five yards: locking/unlocking doors, disabling the alarm, triggering the horn and headlights, and immobilizing/preventing engine start while parked (the flaw cannot start or drive a moving vehicle). Devices continue to broadcast BLE beacons while the engine is running and for up to ten minutes after shutdown, extending the practical attack window. The researchers characterized a compounding real-world theft chain: an attacker uses the Bluetooth flaw to unlock the vehicle silently (no window smash, no forced-lock alarm trigger), then uses commercially available locksmith key-cloning tools to clone an ignition key from the vehicle's own computer -- enabling theft without ever triggering the alarm the device was sold to provide. UCSD professor Stefan Savage described the issue as "probably the worst" car-hacking vulnerability he has encountered.

A second, independently concerning finding is passive location tracking: KARR-SWDS devices continuously broadcast a stable BLE identifier that is picked up and logged by crowdsourced wardriving databases such as WiGLE. Feeding a device's identifier into WiGLE lets an attacker reconstruct a vehicle's historical parking locations -- one outlet called it "a stalker's dream" -- and researchers and outlets characterized this as a stalking-enabling capability that is, in some respects, more concerning than the unlock flaw itself. Researchers used the same WiGLE data to estimate device population, initially counting 1.4 million vulnerable vehicles and refining the estimate to at least 2.2 million after further analysis that accounted for secondhand-market resale distribution across the United States, Canada, and Japan; a field test found 97 vulnerable vehicles within a 20-minute drive of the UCSD campus.

A related aftermarket vendor, Rockledge, ships BLE remote-control alarm/immobilizer hardware that researchers found may also be vulnerable, but via a higher-complexity capture-replay attack: rather than a single static universal key, an attacker must be physically present to intercept and record a legitimate owner's BLE pairing/command exchange, then replay it later to gain access. Rockledge's exposure remained unvalidated by researchers at time of publication.

Researchers privately disclosed the vulnerabilities to Acrisure and to the National Highway Traffic Safety Administration (NHTSA) in January 2025. Acrisure Protection Group released a firmware patch on 2026-07-20 -- roughly 18 months after disclosure, a delay coverage explicitly contrasted with Subaru's reported 24-hour turnaround on an unrelated vulnerability -- but public statements from the company described the research as "highly complex" and presenting "low risk to customers under real-world conditions," a characterization multiple outlets noted conflicts directly with the researchers' own "straightforward" and "scalable" assessment. The fix is not delivered automatically: owners must download the KARR Security app (iOS or Android, open to any user regardless of subscription status), pair it with the vehicle's KARR/SWDS hardware (identifiable via a driver-side window sticker or a small blinking-light button under the dashboard), enter the last eight digits of the VIN, and manually trigger "Customer Service > Firmware Update." Because the KARR-SWDS ecosystem sits outside automaker OTA update channels, there is no centralized push-patch mechanism, and researchers estimate roughly half of affected owners never activated or paid for the alarm service and are unaware the hardware -- or the need to patch it -- exists, leaving an estimated ~1 million of the 2.2 million-unit fleet perpetually unpatched. The research, titled "BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems," is scheduled for coordinated public presentation at DEF CON 34 (2026-08-09, Las Vegas) and the USENIX Security Symposium (2026-08-12, Baltimore). No CVE has been assigned to this issue as of publication.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1596.005 Scan Databases
- T1592.001 Hardware
- T1592.004 Client Configurations
- T1587.001 Malware
- T1588.002 Tool
- T1059 Command and Scripting Interpreter
- T1005 Data from Local System
- T1119 Automated Collection
- T1213 Data from Information Repositories
- T1552.001 Credentials In Files
- T1046 Network Service Discovery
- T1120 Peripheral Device Discovery
- T1078 Valid Accounts
- T1199 Trusted Relationship
- T1550 Use Alternate Authentication Material
- T1685 Disable or Modify Tools
- T1489 Service Stop
- T1657 Financial Theft

## Sources

- [KARR Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks](https://cybersecuritynews.com/karr-bluetooth-vulnerability-exposes/)
- [2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft](https://today.ucsd.edu/story/2-million-cars-with-anti-theft-systems-installed-by-dealers-are-at-higher-risk-of-theft)
- [2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft (EurekAlert)](https://www.eurekalert.org/news-releases/1136978)
- [Anyone in Bluetooth Range Can Unlock Cars, Kill Engines Through Alarms Owners May Never Have Paid For](https://www.thedrive.com/news/anyone-in-bluetooth-range-can-unlock-cars-kill-engines-through-alarms-owners-may-never-have-paid-for)
- [KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars](https://gbhackers.com/karr-bluetooth-vulnerability/)
- [KARR Car Alarm Flaw Lets Nearby Attackers Unlock and Immobilize Vehicles](https://cyberpress.org/karr-car-alarm-flaw/)
- [KARR Security System Flaw: Update KARR Alarm With iPhone](https://thecyberexpress.com/karr-security-system-flaw/)
- [This iPhone app patches a hidden Bluetooth alarm flaw in millions of cars](https://appleinsider.com/articles/26/07/22/if-youve-got-this-dealer-installed-car-alarm-patch-it-today-with-your-iphone)
- [2 million cars at risk of sneaky Bluetooth hack that unlocks doors](https://www.popsci.com/technology/car-bluetooth-cybersecurity-hack/)
- [Millions of cars could be tracked and unlocked by a hidden security flaw](https://www.malwarebytes.com/blog/bugs/2026/07/millions-of-cars-could-be-tracked-and-unlocked-by-a-hidden-security-flaw)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1701
