KARR Bluetooth Flaw Exposes 2.2M Cars to Remote Attacks

A recently uncovered Bluetooth vulnerability in the KARR Security System has put approximately 2.2 million vehicles at risk of remote attacks, enabling unauthorized access to vehicle functions such as door unlocking, alarm control, and engine immobilization.

The KARR system, commonly installed by dealerships as a protective measure before vehicle sale, often remains in place even when buyers opt not to activate the service. This practice has resulted in a vast number of vehicles emitting Bluetooth signals, making them susceptible to exploitation.

Details of the KARR Bluetooth Vulnerability

Researchers from the University of California, San Diego, identified that an attacker within Bluetooth range can issue commands to the vehicle’s alarm system. These commands include locking or unlocking doors, disabling the alarm, activating lights and horns, and preventing the engine from starting. While this flaw doesn’t allow remote driving or control of a moving vehicle, it significantly lowers the barrier for theft by granting silent access to the vehicle’s interior.

The core issue stems from a shared authentication key embedded in all KARR devices. By reverse-engineering the official KARR mobile application, researchers extracted this universal key and developed a proof-of-concept Android app capable of impersonating legitimate users. This tool successfully demonstrated attacks on multiple vehicles without requiring device-specific exploits.

Challenges in Mitigation

Addressing this vulnerability is complex due to the aftermarket nature of the KARR system, which isn’t integrated into manufacturers’ native systems. Consequently, traditional over-the-air updates or manufacturer recalls don’t apply. Acrisure Protection Group, the company behind KARR, released a firmware patch on July 20, 2026, following responsible disclosure in January 2025. However, vehicle owners must manually check for KARR hardware and install the update through the KARR mobile app.

Beyond the immediate risks of exploitation, the vulnerability raises privacy concerns. The KARR system continuously emits identifiable Bluetooth signals while the vehicle is in use and for a short period after shutdown. Researchers utilized the WiGLE wireless tracking database to estimate the widespread deployment of these systems and demonstrated how historical signal data could potentially reveal vehicle movement patterns or frequently visited locations.

During a short drive near San Diego, researchers detected signals from nearly 100 KARR-equipped vehicles, highlighting the extent of the issue.

This situation underscores the critical need for robust security measures in aftermarket automotive systems. Vehicle owners should proactively verify the presence of such systems and ensure they are updated to mitigate potential risks. Additionally, manufacturers and third-party vendors must prioritize security in their designs and provide clear, accessible means for consumers to apply necessary updates.