3 min read

2.2 million cars exposed by dealer anti-theft flaw

UC San Diego researchers found a Bluetooth flaw in dealer-installed KARR-SWDS systems that can let thieves unlock and immobilize cars remotely.

Image: TechXplore

At least 2.2 million cars are vulnerable to a Bluetooth attack that can let thieves lock or unlock doors and immobilize engines remotely, according to researchers at the University of California San Diego.

The issue affects vehicles fitted with KARR-SWDS devices, typically installed by dealerships as inventory-management and anti-theft tools. Researchers said attackers can access affected cars from as far as 5 yards (4.6 meters) away over Bluetooth. Most of the vulnerable vehicles were sold at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to today, though many have since entered the used-car market across the United States, Canada, and Japan.

Many affected cars have a “KARR” or “SWDS” sticker on the driver’s-side window. The device is usually installed beneath the dashboard on the driver’s side and pairs with a smartphone app that can mimic key-fob functions, including locking and unlocking doors, honking the horn, flashing headlights, and preventing the car from starting if it is not already running.

The core problem, the researchers found, is that all KARR-SWDS devices use the same secure key. Once that key was cracked, the team could access any vehicle using the system.

Recommended reading

SharePoint flaw now used to steal machine keys

“Many car owners don’t even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study.”

Aaron Schulman, professor in the UC San Diego Department of Computer Science and Engineering

According to Jerry Yu, a computer science Ph.D. student in Schulman’s group and a co-first author on the paper, thieves would not need to smash a window to get inside. After unlocking the car remotely, they could use tools available to locksmiths to start it and drive away.

Patch and affected systems

The researchers initially identified at least 1.4 million vulnerable vehicles, then later raised that estimate to at least 2.2 million. They disclosed the issue to manufacturers, vendors, and the National Highway Traffic Safety Administration.

Acrisure, which makes the KARR-SWDS devices, released a patch on July 20, 2026. The fix requires vehicle owners to update the device firmware through the KARR app. The researchers said removing the hardware is difficult because it is wired deeply into the dashboard, ignition system, and vehicle computers.

A separate company, Rockledge, makes similar devices. UC San Diego researchers said those may also be vulnerable, but exploiting them appears harder because an attacker would need to intercept and replay a driver’s digital interactions. The team said it had not been able to validate those findings because Rockledge had not responded to the disclosure at the time of writing.

How the flaw was found

The discovery began in 2018, when researchers led by former UC San Diego Ph.D. student Nishant Baskar spotted unfamiliar Bluetooth fingerprints while searching for credit-card skimmers in gas pumps. That trail led them to devices made by Acrisure and Rockledge, which they then analyzed as part of a broader effort to study Bluetooth device security.

The team also found that public databases store location information about vehicles equipped with these devices, potentially making it easier for attackers to track specific cars they want to target.

The researchers plan to present their findings at DEF CON on Aug. 9, 2026, in Las Vegas, and at the USENIX Security conference on Aug. 12 in Baltimore, Maryland. They argue that future systems should require physical interaction inside the car—such as pressing a button—before a new smartphone can connect over Bluetooth.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechXplore

// Keep reading