Millions of Vehicles Vulnerable to Bluetooth Exploit in Aftermarket Anti-Theft Devices
A severe security flaw in the KARR Security System, an aftermarket anti-theft device installed in at least two million vehicles, has exposed drivers to potential remote hacking. Researchers from the University of California, San Diego (UCSD) demonstrated that attackers could exploit the vulnerability to wirelessly unlock doors, disable ignition, honk horns, or flash headlights all without physical access to the car.
The compromised device, originally marketed to dealerships as a theft-prevention tool, was installed in models from Honda, Toyota, Mazda, Ford, and Jeep between 2015 and 2026. Many affected vehicles have since been resold, spreading the risk to drivers in the U.S., Canada, and Japan who may be unaware of the device’s presence. The flaw stems from a shared authentication key across all KARR devices, effectively allowing hackers to bypass security with minimal effort akin to a universal password.
While the exploit cannot start the engine remotely, researchers warned that thieves could combine the Bluetooth hack with key-cloning tools to extract a vehicle’s digital key and drive away undetected. The attack eliminates the need for forced entry, reducing the risk of alarms or visible damage.
Acrisure Protection Group, the parent company of KARR Security, was notified of the vulnerability in January 2025 but only released a software patch in July 2026. In a statement, KARR downplayed the risk, calling the exploit "highly complex" and unlikely under real-world conditions. However, UCSD researchers who plan to present their findings at Def Con in August 2026 disagreed, with one expert calling it "probably the worst" car-hacking threat in years.
Drivers with active KARR subscriptions can update their devices via the app, while others must use their vehicle identification number (VIN) to access the fix. Many affected cars bear a "KARR" or "SWDS" sticker on the driver-side window, and the device itself appears as a small blinking button under the dashboard. However, removing it improperly could disrupt critical systems.
The incident underscores the growing cybersecurity risks of connected vehicles, where over-the-air updates and third-party integrations create new attack surfaces. While modern cars benefit from rapid software fixes, their increasing reliance on digital systems demands heightened vigilance from manufacturers and owners alike.
Source: https://www.popsci.com/technology/car-bluetooth-cybersecurity-hack/
Toyota Motor Corporation cybersecurity rating report: https://www.rankiteo.com/company/toyota
Mazda Motor Corporation cybersecurity rating report: https://www.rankiteo.com/company/mazda-motor-corporation
"id": "TOYMAZ1784925193",
"linkid": "toyota, mazda-motor-corporation",
"type": "Vulnerability",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'At least 2 million vehicles',
'industry': 'Automotive security',
'location': 'U.S.',
'name': 'KARR Security System (Acrisure Protection '
'Group)',
'type': 'Aftermarket anti-theft device manufacturer'},
{'industry': 'Automotive',
'location': 'Global',
'name': 'Honda',
'type': 'Automaker'},
{'industry': 'Automotive',
'location': 'Global',
'name': 'Toyota',
'type': 'Automaker'},
{'industry': 'Automotive',
'location': 'Global',
'name': 'Mazda',
'type': 'Automaker'},
{'industry': 'Automotive',
'location': 'Global',
'name': 'Ford',
'type': 'Automaker'},
{'industry': 'Automotive',
'location': 'Global',
'name': 'Jeep',
'type': 'Automaker'}],
'attack_vector': 'Bluetooth',
'customer_advisories': 'Drivers with active KARR subscriptions can update '
'their devices via the app. Others must use their VIN '
"to access the fix. Look for 'KARR' or 'SWDS' stickers "
'on the driver-side window or a small blinking button '
'under the dashboard.',
'date_detected': '2025-01',
'date_publicly_disclosed': '2026-08',
'date_resolved': '2026-07',
'description': 'A severe security flaw in the KARR Security System, an '
'aftermarket anti-theft device installed in at least two '
'million vehicles, has exposed drivers to potential remote '
'hacking. Researchers demonstrated that attackers could '
'exploit the vulnerability to wirelessly unlock doors, disable '
'ignition, honk horns, or flash headlights without physical '
'access to the car. The flaw stems from a shared '
'authentication key across all KARR devices, allowing hackers '
'to bypass security with minimal effort.',
'impact': {'brand_reputation_impact': 'Negative impact on KARR Security and '
'affected automakers',
'operational_impact': 'Potential unauthorized vehicle access, '
'theft risk, disruption of vehicle functions',
'systems_affected': 'Vehicle anti-theft systems, door locks, '
'ignition, horns, headlights'},
'investigation_status': 'Completed',
'lessons_learned': 'The incident underscores the growing cybersecurity risks '
'of connected vehicles, where over-the-air updates and '
'third-party integrations create new attack surfaces. '
'Heightened vigilance is required from manufacturers and '
'owners.',
'post_incident_analysis': {'corrective_actions': 'Software patch to address '
'the shared key '
'vulnerability, improved '
'security protocols for '
'future devices',
'root_causes': 'Shared authentication key across '
'all KARR devices, lack of unique '
'security credentials'},
'recommendations': 'Drivers should update their KARR devices via the app or '
'VIN-based fix. Automakers and aftermarket device '
'manufacturers should enforce stricter security standards, '
'including unique authentication keys and regular '
'vulnerability assessments.',
'references': [{'source': 'University of California, San Diego (UCSD) '
'researchers'},
{'source': 'Def Con presentation (August 2026)'}],
'response': {'communication_strategy': 'Public disclosure at Def Con (August '
'2026), company statement downplaying '
'risk',
'containment_measures': 'Software patch released in July 2026',
'remediation_measures': 'Device update via app or VIN-based fix',
'third_party_assistance': 'University of California, San Diego '
'(UCSD) researchers'},
'stakeholder_advisories': 'Affected automakers and KARR Security advised to '
'notify customers and provide updates.',
'title': 'Millions of Vehicles Vulnerable to Bluetooth Exploit in Aftermarket '
'Anti-Theft Devices',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'Shared authentication key across all KARR devices'}