Millions of drivers with a dealer-installed KARR alarm should download the iPhone app and install the latest firmware update now, because a security flaw can let nearby attackers unlock or immobilize more than two million vehicles.

The affected KARR Security System is an aftermarket alarm that dealerships install to protect vehicles on their lots. Dealers often leave the hardware connected after a vehicle is sold, even when the buyer declines to pay for the alarm service.

The vulnerability affects dealer-installed KARR hardware, not the automakers' factory systems. It doesn't affect Apple CarPlay, the iPhone-to-car connection or Apple's software.

Because KARR is third-party equipment, automakers can't distribute the fix through their usual software update systems. The unusual arrangement places the problem outside the normal vehicle security process.

Researchers at the University of California, San Diego, demonstrated that an attacker within Bluetooth range could lock or unlock a vehicle, disable its alarm, sound its horn, flash its lights or prevent a parked vehicle from starting. The vulnerability can't remotely start a vehicle or take control while it's moving.

Acrisure Protection Group, which sells the KARR system, released a firmware update on July 20. The UC San Diego team said owners who already use the KARR Security app should receive an update alert.

Owners who don't have the app need to download it for iPhone or Android, connect it to the alarm and select "customer service" followed by "firmware update."

Researchers first reported the vulnerability to Acrisure in January 2025, about 18 months before the company released its patch. The update arrived before the researchers' scheduled presentations at DEF CON on August 9 in Las Vegas and the USENIX Security Symposium on August 12 in Baltimore.

Acrisure said the attack was highly complex and presented a low risk under real-world conditions. The company said it would notify owners through the KARR app, its website and communications with dealerships.

The hidden alarm makes the KARR vulnerability harder to fix

The KARR flaw creates an unusual security problem because the vulnerable hardware sits outside the automaker's normal supply and support systems. UC San Diego researchers estimate that at least half of owners with the device installed didn't request it.

Dealerships often installed KARR systems across their inventory and left the hardware connected after buyers declined the paid feature. The system remained in the vehicle in a deactivated state instead of being removed.

Researchers found that deactivated systems still broadcast and accept Bluetooth signals while the vehicle is running and for up to 10 minutes after it's turned off. An attacker could activate the KARR system remotely before sending additional commands.

Close-up of a cylindrical electronic connector with a bundle of multicolored wires attached, lit with blue and orange highlights against a dark, blurred backgroundThe KARR Security System. Image credit: David Baillot/University of California San Diego

For owners who declined the service, that activation may briefly sound the horn and flash the lights. Researchers said customers who paid to activate KARR wouldn't receive the same warning when an unauthorized device sent commands.

Owners can check for a KARR sticker on the driver-side window, an "SWDS" sticker referring to SouthWest Dealer Services or a small button with a blinking light beneath the dashboard.

Researchers found affected systems across the United States and in other countries. UC San Diego said most identified vehicles were purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California from 2017 through July 21.

The vulnerability affects dealer-installed KARR hardware, not the automakers' factory systems.

A shared Bluetooth key exposed affected KARR systems

The flaw stems from an authentication key shared by the affected Bluetooth-enabled KARR systems. Researchers found the key in the official KARR smartphone app while reverse engineering the system's Bluetooth communications.

The weakness resembles other Bluetooth attacks that allow malicious software or hardware to pose as a trusted device.

The team built a proof-of-concept Android app that posed as the official software and sent commands to nearby vulnerable alarms. Researchers used it to unlock vehicles, prevent parked vehicles from starting and trigger the horns and lights of several vehicles at once.

Map of the United States with blue circles showing data values by city; larger circles in California and eastern states, smaller circles elsewhere, with size legend from 1K to 1MThe UCSD researchers' estimates of the locations of vulnerable cars across the US, based in part on radio signals collection crowdsourced in the WiGLE database. Image credit: UCSD Research Team

The KARR vulnerability alone doesn't let an attacker start and drive away with a vehicle. It can allow a thief to enter without breaking a window or triggering the alarm.

Researchers showed that a thief already inside could use a commercially available locksmith tool to create a working key within minutes. The KARR flaw could provide quiet access to the cabin without requiring door-opening tools that might trigger the alarm.

Acrisure's description of the attack as highly complex needs context. The researchers needed technical expertise to reverse engineer the app and create their software, but they demonstrated the resulting commands using a standard Android phone running their custom app.

Neither UC San Diego nor Wired reported evidence that criminals had exploited the flaw against vehicle owners. The universal key still created a serious risk because the same technique worked across the affected Bluetooth-enabled devices instead of requiring a separate exploit for each vehicle.

Acrisure's response follows the familiar security practice of addressing a hardware weakness through a firmware update. KARR owners face the added challenge of determining whether the affected hardware is inside their vehicle before they can install it.

KARR Bluetooth signals may expose vehicle locations

The KARR system creates a separate privacy risk by broadcasting an identifiable Bluetooth signal while the vehicle is running and for up to 10 minutes after it's turned off. UC San Diego researchers used the crowdsourced wireless database WiGLE to estimate that at least 2.2 million Bluetooth-enabled KARR systems had been deployed.

WiGLE records where contributors detected wireless devices. Researchers warned that someone could use those historical records to identify locations where a particular KARR-equipped vehicle had repeatedly been detected.

The concern reflects a wider class of Bluetooth tracking risks in which a device's wireless identifier can reveal its movements or frequently visited locations.

The research doesn't establish that criminals have used WiGLE records to target KARR-equipped vehicles. The location data could still provide a scouting tool by helping an attacker find a vulnerable vehicle before approaching it.

The prevalence of the systems was apparent during a 20-minute drive near the UC San Diego campus. Researchers detected Bluetooth signals from 97 KARR-equipped vehicles using a standard Android phone.

The findings show why dealerships need to disclose connected aftermarket hardware that remains in sold vehicles, explain who is responsible for updates and offer removal when buyers decline the service.

How to protect yourself from the KARR car alarm vulnerability

Drivers should first determine whether their vehicle contains a KARR Security System. Check the driver-side window for KARR or SWDS branding and look beneath the dashboard for a small button with a blinking light.

Affected owners should install the KARR Security app, connect it to the vehicle and open the firmware update option under customer service. Owners who already use the app should open the update notification and confirm that the firmware installation is complete.

Drivers who can't identify the device or complete the update should contact the dealership that sold the vehicle or KARR customer support. Acrisure says its July 20 firmware update addresses the Bluetooth flaw.