Full Report
Millions of drivers with a dealer-installed KARR Security System are being urged to update their KARR alarm using an iPhone or Android device after researchers uncovered a Bluetooth vulnerability that could allow nearby attackers to unlock or immobilize affected vehicles. The flaw impacts more than 2.2 million vehicles equipped with the aftermarket security system, but it does not affect factory-installed vehicle software, Apple CarPlay or Apple's iPhone platform. KARR Security System Vulnerability Affects Dealer-installed Hardware The KARR Security System is installed by dealerships to secure vehicles on their lots. In many cases, the hardware remains connected even after buyers decline the paid KARR alarm service. Because it is third-party equipment, automakers cannot deliver fixes through their standard software update process. Researchers from the University of California, San Diego found that attackers within Bluetooth range could lock or unlock vehicles, disable alarms, activate horns, flash lights, or prevent parked vehicles from starting. However, they confirmed the flaw cannot remotely start a vehicle or control it while driving. iPhone App Update Fixes KARR Alarm Flaw Acrisure Protection Group, which sells the KARR Security System, released a firmware update on July 20 after researchers privately disclosed the issue in January 2025. Owners using the KARR Security app on an iPhone should receive an update notification. Others must download the app, connect it to the KARR alarm, then navigate to "Customer Service" and "Firmware Update." The patch was released before presentations scheduled for DEF CON on August 9 in Las Vegas and the USENIX Security Symposium on August 12 in Baltimore. Hidden KARR Security System Complicates Updates Researchers estimate at least half of affected owners never requested the KARR Security System. Dealerships often left deactivated hardware installed, yet researchers found these units continued broadcasting Bluetooth signals while vehicles were running and for up to 10 minutes after being switched off. Owners can identify the system by checking for a KARR or "SWDS" sticker on the driver's window or a blinking button beneath the dashboard. Most affected vehicles were purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and July 21, although impacted vehicles were also identified elsewhere. Shared Bluetooth Key Exposes KARR Alarm Devices Researchers discovered a universal authentication key embedded in the official smartphone app while reverse engineering Bluetooth communications. Using a proof-of-concept Android app, they unlocked vehicles, disabled KARR alarm functions, and triggered horns and lights. Although the flaw alone cannot steal a vehicle, researchers said it could provide quiet access before a commercially available locksmith tool creates a working key. Acrisure described the attack as "highly complex" and said the real-world risk is low. Neither UC San Diego nor Wired found evidence of criminals exploiting the vulnerability. Privacy Concerns and Recommended Action Researchers also warned that Bluetooth signals from the KARR Security System could reveal vehicle locations. Using the WiGLE wireless database, they estimated at least 2.2 million Bluetooth-enabled systems had been deployed and detected 97 KARR-equipped vehicles during a 20-minute drive near the UC San Diego campus. Drivers should confirm whether their vehicle contains a KARR Security System, install the latest firmware using the iPhone or Android app, and contact their dealership or KARR support if they cannot complete the update.
Analysis Summary
# Vulnerability: KARR Security System Universal Bluetooth Authentication Key
## CVE Details
- **CVE ID:** Not yet assigned (Disclosed by UC San Diego researchers)
- **CVSS Score:** N/A (Estimated High/Critical based on unauthorized physical access)
- **CWE:** CWE-321 (Use of Hard-coded Cryptographic Key)
## Affected Systems
- **Products:** KARR Security System (Dealer-installed aftermarket hardware)
- **Versions:** Hardware deployed between 2017 and July 2024
- **Configurations:** Impacts approximately 2.2 million vehicles, primarily from Honda, Toyota, Mazda, Ford, and Jeep dealerships. Note: Hardware may be present and active even if the owner did not purchase the security service.
## Vulnerability Description
Researchers discovered a **universal authentication key** embedded within the official KARR smartphone application code. By reverse-engineering the Bluetooth Low Energy (BLE) communications between the app and the vehicle hardware, attackers can use this shared key to bypass security measures. The vulnerability allows an attacker within Bluetooth range to spoof authorized commands to the vehicle's security module.
## Exploitation
- **Status:** PoC available (Developed by UC San Diego researchers)
- **Complexity:** Medium (Requires reverse-engineering knowledge, though the vendor classifies it as "highly complex")
- **Attack Vector:** Adjacent (Bluetooth range)
## Impact
- **Confidentiality:** Medium (Bluetooth signals can be used to track/reveal vehicle location via databases like WiGLE)
- **Integrity:** High (Attackers can lock/unlock doors, disable alarms, and toggle horns/lights)
- **Availability:** High (Attackers can trigger the starter disable/immobilizer feature, preventing the vehicle from starting)
## Remediation
### Patches
- **Firmware Update:** Released July 20, 2024.
- **Action Required:** Users must download/update the **KARR Security app** on iPhone or Android, connect to their vehicle, and navigate to **Customer Service > Firmware Update** to push the patch to the hardware.
### Workarounds
- **Hardware Removal:** Owners can have a technician physically remove the third-party KARR module if they do not wish to use the service or the app.
- **Verification:** Check for a "KARR" or "SWDS" sticker on the driver-side window or a blue blinking button/LED beneath the dashboard to confirm the system's presence.
## Detection
- **Indicators of Compromise:** Unusual behavior of vehicle peripherals (horns honking, lights flashing, or unexpected door unlocking) without user input.
- **Detection Methods:** Researchers utilized the **WiGLE wireless database** to identify broadcasting KARR Bluetooth signals. Owners can use generic Bluetooth scanning apps to look for active "KARR" or "SWDS" signals emanating from the vehicle.
## References
- **University of California, San Diego (Research Team)**
- **Wired Disclosure:** hxxps://www[.]wired[.]com/story/karr-alarm-vulnerability-immobilize-cars/
- **Vendor (Acrisure Protection Group):** hxxps://www[.]karrsecurity[.]com/