4 min read

2 Million Cars May Hide a Hackable KARR Device

UC San Diego researchers say a dealer-installed KARR alarm in more than 2 million vehicles can be abused over Bluetooth. A firmware patch is now available.

Image: Wired

A dealer-installed alarm system buried in cars across the US has left more than 2 million vehicles vulnerable to hacking, according to researchers at UC San Diego. The issue affects the Bluetooth-enabled KARR Security System, an aftermarket device often added by dealerships to prevent theft on dealer lots, then left in place after the car is sold.

The researchers say an attacker within Bluetooth range could silently unlock a car, disable its alarm, honk the horn or flash the lights, or even disable the ignition and leave the driver stranded. In many cases, owners may not realize the hardware is installed at all.

The KARR Security System has been wired into the critical systems of more than 2 million vehicles by UCSD's estimate all...
The KARR Security System has been wired into the critical systems of more than 2 million vehicles by UCSD's estimate all...

“It’s designed to make cars more secure, but ultimately it’s created a vulnerability that needs to be patched immediately across millions vehicles. We’re trying to get the word out that you need to check your car for this device and manually patch it now.”

Aaron Schulman, UC San Diego computer science professor

Acrisure Protection Group, which sells the KARR system, has released a firmware update. Owners with the KARR Security app installed should receive an alert, UCSD says. Others will need to install the app on Android or iOS, connect it to the car’s KARR alarm, then tap “customer service” and “firmware update.”

Owners can check for the device by looking for a KARR sticker on the driver-side window, or in some cases an “SWDS” sticker for SouthWest Dealer Services, plus a small button with a blinking light under the dashboard. The researchers say Southern California drivers are especially likely to have it, though they found the devices across the US and in other countries.

How the KARR flaw works

The core problem, the researchers found, is that all KARR devices share a single authentication key. That key was also visible in the KARR smartphone app’s code. By reverse-engineering the app, the team built its own Android tool that could send accepted commands to nearby KARR-equipped cars.

Recommended reading

Estée Lauder discloses Oracle breach nearly a year later

The UCSD teams proof of concept app offers a menu of hacking options that the KARR vulnerability makes possible …
The UCSD teams proof of concept app offers a menu of hacking options that the KARR vulnerability makes possible …

The vulnerability does not let attackers start a car directly. But the team showed that once inside, a thief could use a locksmith tool commonly available for resale online to create a working key in a few minutes. Combined with the KARR flaw, that could make theft quieter and easier.

Even cars where buyers declined to pay for the KARR system can still be exposed. The researchers say those “deactivated” devices continue to broadcast and accept Bluetooth signals while the car is on, and for up to 10 minutes after it is turned off. Attackers can reactivate them remotely and immediately issue commands. For unpaid, deactivated systems, that process causes only a brief horn beep and light flash; paying customers would receive no such warning.

Acrisure said in a statement that the issue is “highly complex” and presents “a low risk to customers under real-world conditions,” while adding that it developed a firmware update. But UCSD says the company was notified in January of last year, and the patch arrived only weeks before the team planned to present its findings at Defcon and Usenix next month.

How widespread the KARR alarms appear to be

UCSD researcher Nishant Bhaskar first noticed the devices in 2018 while analyzing radio-enabled skimmers at gas stations. He later realized the same Bluetooth signals were coming from vehicles of many makes and models. In 2024, graduate researcher Jerry Yu examined the KARR app and found the universal key.

“Once we reverse-engineered their application, we quickly realized after understanding their internal authentication protocol that it was so simple that we could extract it and re-implement it as our own application, which we did.”

Jerry Yu, researcher

To estimate the scale, Yibo Wei used the crowdsourced radio database WiGLE and device serial numbers, arriving at an estimate of more than 2 million Bluetooth-enabled KARR units.

The UCSD researchers estimates of the locations of vulnerable cars across the US based in part on radio signals...
The UCSD researchers estimates of the locations of vulnerable cars across the US based in part on radio signals...

Those WiGLE records could also be used to trace where vulnerable vehicles have been seen before and where they are often parked, the researchers warn. In one 20-minute drive near the UCSD campus, the team found 97 vehicles broadcasting KARR signals with a standard Android phone.

Stefan Savage, a UCSD computer science professor who was not involved in the research, told WIRED the flaw is “probably the worst” car hacking threat yet discovered because affected drivers may not know the device exists, and automakers cannot fix it for them.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via Wired

// Keep reading