Millions of Vehicles Vulnerable to Remote Attacks via Flawed KARR Security System
Researchers at the University of California, San Diego, have uncovered a critical Bluetooth vulnerability in the aftermarket KARR Security System, exposing an estimated 2.2 million vehicles to remote attacks. The flaw allows unauthorized access to key functions, including door unlocking, alarm deactivation, and engine immobilization, though it does not enable remote driving control.
The vulnerability stems from a hardcoded authentication key embedded in all KARR devices. By reverse-engineering the official KARR mobile app, researchers extracted this universal key and developed a proof-of-concept Android app capable of impersonating legitimate users. Attacks can be executed within Bluetooth range, making the exploit scalable across all affected systems.
The KARR system is commonly installed by dealerships as a theft deterrent for vehicles on their lots, but the hardware often remains in place even if buyers opt out of the service. Many owners are unaware their vehicles are equipped with the system, which continues to emit Bluetooth signals regardless of activation status.
Researchers mapped vulnerable vehicles across the U.S. using WiGLE radio signal data, detecting nearly 100 KARR-equipped vehicles during a short drive near San Diego. Beyond active exploitation risks, the system’s persistent Bluetooth emissions raise privacy concerns, as historical signal data could reveal vehicle movement patterns.
Acrisure Protection Group, the parent company of KARR, released a firmware patch on July 20, 2025, following responsible disclosure in January. However, mitigation is complicated by the system’s aftermarket nature traditional over-the-air updates or manufacturer recalls do not apply. Owners must manually check for KARR hardware (often labeled on windows or under the dashboard) and install the update via the KARR app.
The incident highlights a broader issue in automotive cybersecurity, where third-party hardware can bypass manufacturer security controls, leaving consumers and automakers with limited visibility and delayed response options.
Source: https://cybersecuritynews.com/karr-bluetooth-vulnerability-exposes/
Acrisure Protection Group cybersecurity rating report: https://www.rankiteo.com/company/acrisurepg
"id": "ACR1784795082",
"linkid": "acrisurepg",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '2.2 million vehicles',
'industry': 'Automotive Security',
'location': 'United States',
'name': 'KARR Security System (Acrisure Protection '
'Group)',
'type': 'Aftermarket vehicle security system'}],
'attack_vector': 'Bluetooth',
'customer_advisories': 'Vehicle owners should manually verify if their '
'vehicle has KARR hardware and install the firmware '
'patch via the KARR app.',
'data_breach': {'personally_identifiable_information': 'Vehicle movement '
'patterns (privacy '
'concern)'},
'date_detected': '2025-01-01',
'date_resolved': '2025-07-20',
'description': 'Researchers at the University of California, San Diego, '
'uncovered a critical Bluetooth vulnerability in the '
'aftermarket KARR Security System, exposing an estimated 2.2 '
'million vehicles to remote attacks. The flaw allows '
'unauthorized access to key functions, including door '
'unlocking, alarm deactivation, and engine immobilization. The '
'vulnerability stems from a hardcoded authentication key '
'embedded in all KARR devices, enabling attackers to '
'impersonate legitimate users within Bluetooth range.',
'impact': {'brand_reputation_impact': 'High',
'operational_impact': 'Unauthorized access to vehicle functions '
'(door unlocking, alarm deactivation, engine '
'immobilization)',
'systems_affected': '2.2 million vehicles'},
'investigation_status': 'Resolved',
'lessons_learned': 'Third-party automotive hardware can bypass manufacturer '
'security controls, leaving consumers and automakers with '
'limited visibility and delayed response options.',
'post_incident_analysis': {'corrective_actions': 'Firmware patch released, '
'public advisories issued '
'for manual updates.',
'root_causes': 'Hardcoded authentication key in '
'KARR devices, lack of secure '
'update mechanisms for aftermarket '
'systems.'},
'recommendations': 'Vehicle owners should manually check for KARR hardware '
'and install the firmware update via the KARR app. '
'Automakers and aftermarket vendors should improve '
'security oversight and update mechanisms for third-party '
'systems.',
'references': [{'source': 'University of California, San Diego'}],
'response': {'communication_strategy': 'Public disclosure and advisory for '
'vehicle owners',
'containment_measures': 'Firmware patch released',
'remediation_measures': 'Manual firmware update via KARR app',
'third_party_assistance': 'University of California, San Diego '
'researchers'},
'stakeholder_advisories': 'Automakers, dealerships, and vehicle owners '
'advised to check for KARR hardware and apply '
'updates.',
'title': 'Millions of Vehicles Vulnerable to Remote Attacks via Flawed KARR '
'Security System',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'Hardcoded authentication key'}