A team of cybersecurity researchers at UC San Diego has uncovered a severe vulnerability in an aftermarket car alarm system installed on over two million vehicles across the United States. The device, known as the KARR Security System, can be exploited by any attacker within Bluetooth range to unlock doors, disable the alarm, honk the horn, flash lights, or even disable the ignition, potentially leaving drivers stranded.
Dealer-installed without buyers' knowledge
The KARR alarm is typically installed by car dealerships as a theft deterrent on showroom vehicles. When the car is sold, the alarm often remains in place even if the buyer declines to pay for the feature. According to researcher estimates, at least half of car owners with the device are unaware of its presence. This means millions of motorists have a vulnerable component under their hood that no car manufacturer can fix on its own.
The attack vector: a shared authentication key
The researchers identified a single authentication key shared across all KARR devices, which they also found inside the official KARR smartphone app. By reverse-engineering the app, they created a custom tool that can send radio commands accepted by any nearby KARR device. With a tap on a phone, an attacker can silently unlock a car at a stoplight, immobilize a parked vehicle, or trigger a chaotic symphony of horns and flashing lights across multiple cars simultaneously.
Sponsored Protocol
Real-world risks: theft and sabotage
While the KARR alarm does not allow the engine to be started, the researchers demonstrated that once inside the vehicle (by exploiting the unlock vulnerability), a thief can use a commonly available locksmith tool to create a working key within minutes and drive away. The flaw affects both active and deactivated KARR units: even in deactivated mode, the device continues to broadcast Bluetooth signals for up to ten minutes after the car is turned off and can be reactivated remotely without any warning to the owner, except for a brief horn beep and light flash.
Sponsored Protocol
The fix: update firmware via the app
Acrisure Protection Group, the company behind KARR, has released a firmware patch to address the vulnerability. Users who already have the KARR Security app installed will receive an update notification; others need to download the app (available for Android and iOS), connect it to their vehicle's KARR device, and follow the instructions to update. To check if a car has the device, look for a KARR sticker on the driver-side window or a SWDS (SouthWest Dealer Services) sticker, as well as a small button with a blinking light under the dashboard.
A broader threat to automotive security
Professor Stefan Savage, another UC San Diego security expert who co-led the first car-hacking team in 2010, called this flaw "probably the worst car hacking threat ever discovered" due to its scale, the difficulty of reaching affected owners, and the potential for criminal misuse. The KARR vulnerability joins a growing list of risks from aftermarket devices: as highlighted in a report on a smart photography robot (Insta360 unveils Cameraman project), unregulated tech can introduce serious privacy and security issues. For more background on car alarm systems, see Wikipedia's entry on car alarms.
Sponsored Protocol
The researchers are set to present their findings at the Defcon and Usenix security conferences next month. In the meantime, they urge all drivers to check their vehicles and apply the patch immediately. Ignoring the problem could have concrete consequences: a thief could enter your car in seconds, leaving no trace, and steal or sabotage it.