Millions of Cars Vulnerable to Stealth Hacking via Unwanted Aftermarket Alarm Systems
A critical vulnerability has been discovered in the **KARR Security System**, an aftermarket car alarm installed in an estimated two million vehicles across the U.S. without many owners' knowledge. This flaw allows hackers within Bluetooth range to remotely unlock cars, disable alarms, and even immobilize vehicles, posing significant risks for theft, tracking, and roadside paralysis.
Modern vehicles, increasingly resembling computers on wheels, demand regular security updates. However, a recent discovery by security researchers at **UC San Diego** reveals a more insidious threat: an insecure third-party component, often installed without the owner's consent or knowledge, wired into the vehicle's most sensitive systems.
The **KARR Security System**, a popular aftermarket car alarm, has been identified as having a severe Bluetooth vulnerability. Researchers demonstrated that any hacker within Bluetooth range can send radio commands to silently unlock a car, disable its alarm, control its horn and lights, or even disable its ignition, leaving drivers stranded.
### The Unseen Threat Under the Hood
These **KARR** alarm devices are typically installed by car dealers, primarily as a theft deterrent for their lots. Crucially, they are often not removed when the car is sold, even if the buyer declines to pay for the feature. This means millions of car owners are driving vehicles with a hackable device they never purchased and are unaware of.

**Aaron Schulman**, a **UCSD** computer science professor who led the research, emphasized the urgency: "This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars. It's designed to make cars more secure, but ultimately it's created a vulnerability that needs to be patched immediately across millions vehicles. We're trying to get the word out that you need to check your car for this device and manually patch it now.β
### Patching the Problem
The company behind the **KARR Security System**, **Acrisure Protection Group**, has released a firmware update for the vulnerable Bluetooth model. Owners with the **KARR Security** smartphone app should receive an alert. For those without the app, it needs to be downloaded (**Android**, **iOS**), connected to the vehicle's **KARR** alarm, and then the firmware update can be initiated via the βcustomer serviceβ menu.
Identifying if your vehicle has a **KARR** device involves looking for a **KARR** sticker on the driver-side window, or sometimes a sticker reading βSWDSβ for **SouthWest Dealer Services** (a subsidiary of **Acrisure Protection Group**). A small button with a blinking light attached to the underside of the dashboard is another indicator. While prevalent in Southern California, researchers have found these devices across the U.S. and internationally.
### Carjacking, Sabotage, and βMayhemβ
**Stefan Savage**, another **UCSD** computer science professor and co-leader of the first team to hack a car's steering and brakes in 2010-2011, described the **KARR** flaw as βprobably the worstβ car hacking threat ever discovered. He highlighted the scale, the inability of car manufacturers to fix it, and the owners' unawareness as critical factors.
**Acrisure Protection Group** stated to WIRED that the vulnerability is βhighly complex and presents a low risk to customers under real-world conditions.β However, they did confirm a firmware update has been developed and will be communicated via their app, website, and dealer channels. It's noteworthy that the patch took nearly 18 months to release after **UCSD** initially reported the vulnerability in January of last year, only weeks before planned presentations at **Defcon** and **Usenix** security conferences.
The **UCSD** researchers' demonstrations for WIRED contradict **Acrisure Protection Group's** assessment of βlow risk.β Their custom Android app could, with a tap, unlock a car at a stoplight for theft or carjacking, paralyze a parked car, or even trigger a βmayhemβ button to simultaneously activate horns and lights on multiple vulnerable vehicles.

.jpg)