KARR alarm flaw puts 2 million cars at risk of Bluetooth hacking and engine immobilization
> cd .. / HUB_EDITORIALE
News

KARR alarm flaw puts 2 million cars at risk of Bluetooth hacking and engine immobilization

[2026-07-21] Author: Ing. Calogero Bono
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

A team of cybersecurity researchers at UC San Diego has uncovered a severe vulnerability in an aftermarket car alarm system installed on over two million vehicles across the United States. The device, known as the KARR Security System, can be exploited by any attacker within Bluetooth range to unlock doors, disable the alarm, honk the horn, flash lights, or even disable the ignition, potentially leaving drivers stranded.

Dealer-installed without buyers' knowledge

The KARR alarm is typically installed by car dealerships as a theft deterrent on showroom vehicles. When the car is sold, the alarm often remains in place even if the buyer declines to pay for the feature. According to researcher estimates, at least half of car owners with the device are unaware of its presence. This means millions of motorists have a vulnerable component under their hood that no car manufacturer can fix on its own.

The attack vector: a shared authentication key

The researchers identified a single authentication key shared across all KARR devices, which they also found inside the official KARR smartphone app. By reverse-engineering the app, they created a custom tool that can send radio commands accepted by any nearby KARR device. With a tap on a phone, an attacker can silently unlock a car at a stoplight, immobilize a parked vehicle, or trigger a chaotic symphony of horns and flashing lights across multiple cars simultaneously.

Sponsored Protocol

Real-world risks: theft and sabotage

While the KARR alarm does not allow the engine to be started, the researchers demonstrated that once inside the vehicle (by exploiting the unlock vulnerability), a thief can use a commonly available locksmith tool to create a working key within minutes and drive away. The flaw affects both active and deactivated KARR units: even in deactivated mode, the device continues to broadcast Bluetooth signals for up to ten minutes after the car is turned off and can be reactivated remotely without any warning to the owner, except for a brief horn beep and light flash.

Sponsored Protocol

The fix: update firmware via the app

Acrisure Protection Group, the company behind KARR, has released a firmware patch to address the vulnerability. Users who already have the KARR Security app installed will receive an update notification; others need to download the app (available for Android and iOS), connect it to their vehicle's KARR device, and follow the instructions to update. To check if a car has the device, look for a KARR sticker on the driver-side window or a SWDS (SouthWest Dealer Services) sticker, as well as a small button with a blinking light under the dashboard.

A broader threat to automotive security

Professor Stefan Savage, another UC San Diego security expert who co-led the first car-hacking team in 2010, called this flaw "probably the worst car hacking threat ever discovered" due to its scale, the difficulty of reaching affected owners, and the potential for criminal misuse. The KARR vulnerability joins a growing list of risks from aftermarket devices: as highlighted in a report on a smart photography robot (Insta360 unveils Cameraman project), unregulated tech can introduce serious privacy and security issues. For more background on car alarm systems, see Wikipedia's entry on car alarms.

Sponsored Protocol

The researchers are set to present their findings at the Defcon and Usenix security conferences next month. In the meantime, they urge all drivers to check their vehicles and apply the patch immediately. Ignoring the problem could have concrete consequences: a thief could enter your car in seconds, leaving no trace, and steal or sabotage it.

Source: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now

> share
Ing. Calogero Bono

> AUTHOR_EXTRACTED

Ing. Calogero Bono

Ingegnere informatico, fondatore di Meteora Web e Zenith OS. System administrator e progettista di piattaforme, app e CMS proprietari, con esperienza in sviluppo full-stack, marketing digitale ed ecosistema Google.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()