{"id":409871,"date":"2026-07-23T20:38:24","date_gmt":"2026-07-23T20:38:24","guid":{"rendered":"https:\/\/www.newsbeep.com\/us-ca\/409871\/"},"modified":"2026-07-23T20:38:24","modified_gmt":"2026-07-23T20:38:24","slug":"millions-of-california-bought-cars-can-be-hijacked-via-bluetooth","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us-ca\/409871\/","title":{"rendered":"Millions of California-bought cars can be hijacked via Bluetooth"},"content":{"rendered":"<p class=\"kicker \" style=\"\">security<\/p>\n<p class=\"subtitle \" style=\"\">Aftermarket dealer-installed KARR\/SWDS security systems all use the same secure key, say UCSD researchers<\/p>\n<p>At least 2.2 million vehicles fitted with dealer-installed KARR and SWDS security systems are vulnerable to nearby Bluetooth attacks that can unlock doors or prevent a stopped vehicle from starting, according to researchers at the University of California San Diego.<\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/us-ca\/wp-content\/uploads\/2026\/07\/5277342.webp\" width=\"480\" height=\"274\" alt=\"A KARR security system sticker in a vehicle window\" loading=\"lazy\" style=\"\"\/><\/p>\n<p>\n            A KARR security system sticker in a vehicle window<br \/>\n            David Baillot\/UC San Diego Jacobs School of Engineering\n        <\/p>\n<p>An <a href=\"https:\/\/today.ucsd.edu\/story\/2-million-cars-with-anti-theft-systems-installed-by-dealers-are-at-higher-risk-of-theft\" rel=\"nofollow noopener\" target=\"_blank\">advance look<\/a> at the research published by UCSD this week (the <a href=\"https:\/\/par.nsf.gov\/biblio\/10696650\" rel=\"nofollow noopener\" target=\"_blank\">full writeup<\/a> won\u2019t be available until August 12) reveals that KARR and SWDS security devices manufactured by Acrisure contain a serious flaw: They \u201call \u2026 rely on the same secure key,\u201d the researchers found.\u00a0<\/p>\n<p>What that means, according to the researchers, is that anyone who knows the key, has a device with a Bluetooth connection, and can get within five yards of an affected vehicle can unlock it, make the horn honk, flash the headlights, or even prevent it from starting.\u00a0<\/p>\n<p>\u201cInstead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors,\u201d Jerry Yu, coauthor on the research and UCSD compsci graduate, said in the release.\u00a0\u00a0<\/p>\n<p>KARR\/SWDS <a href=\"https:\/\/www.karrsecurity.com\/\" rel=\"nofollow noopener\" target=\"_blank\">devices<\/a> are installed by dealerships. Along with providing key fob-like functions, they also serve as an antitheft device, allowing dealers and buyers to track cars with the devices installed in the case of theft. <\/p>\n<p>According to UCSD, the devices are typically sold as a paid upgrade at dealerships around the US. KARR says its products are available through more than 3,000 dealerships nationwide. Per the researchers, however, those devices remain active even if a buyer declines the service, meaning those who don\u2019t have an active KARR\/SWDS contract are still at risk.\u00a0<\/p>\n<p>\u201cRemoving the devices is not trivial,\u201d UCSD compsci PhD candidate and paper co-author Yibo Wei said in the university\u2019s report on the research. \u201cYou have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car\u2019s computers and ignition system.\u201d\u00a0<\/p>\n<p>In other words, there are likely a lot of cars on the road with one of these units installed, and for many owners, a KARR or SWDS window sticker may be the only obvious indication.<\/p>\n<p>The researchers said that most vulnerable vehicles were purchased in Southern California in the past nine years from Honda, Toyota, Mazda, Ford, and Jeep dealerships. Secondary market resales, however, mean affected vehicles can be found throughout the US and even as far away as Japan, the team noted. They also discovered a public database that stores information about equipped vehicles, according to UCSD.<\/p>\n<p>For those worried their vehicle may be vulnerable, no need to worry: KARR Security has already released a firmware update for affected devices that can be installed by both active customers and those with an inactive security system;\u00a0<a href=\"https:\/\/www.karrsecurity.com\/karr-security-firmware-update-instructions\" rel=\"nofollow noopener\" target=\"_blank\">steps<\/a> are included on the company\u2019s website. It\u2019s not clear if KARR is notifying customers of the need to update their security system &#8211; we asked, but the company didn\u2019t directly respond to that question.\u00a0<\/p>\n<p>What KARR did tell us was that, in contrast to the UCSD finding that \u201call KARR-SWDS devices rely on the same secure key,\u201d it claims that only a small percentage of devices \u201cwith certain Bluetooth-related components\u201d are actually affected.\u00a0<\/p>\n<p>\u201cThe vulnerability described in the research is highly complex and presents a low risk to customers under real-world conditions,\u201d a KARR spokesperson told us. \u201cNevertheless, we responded promptly and developed a firmware update to address the issue.\u201d\u00a0<\/p>\n<p>The vulnerability was discovered serendipitously by the UCSD researchers years ago when they were doing research on <a href=\"https:\/\/www.theregister.com\/security\/2010\/02\/23\/payment-card-skimmer-secretly-planted-in-gas-station-pump\/1101278\" rel=\"nofollow noopener\" target=\"_blank\">credit card skimmers<\/a> and spotted Bluetooth fingerprints they couldn\u2019t identify. After figuring out they had spotted car security systems, the team started digging into the devices, and here we are.\u00a0<\/p>\n<p>We contacted the team to get more detail on their findings, but didn\u2019t hear back. They\u2019ll be presenting their work at DEF CON on August 9, and the USENIX Security conference on August 12. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"security Aftermarket dealer-installed KARR\/SWDS security systems all use the same secure key, say UCSD researchers At least 2.2&hellip;\n","protected":false},"author":2,"featured_media":409872,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[7,9,8],"class_list":["post-409871","post","type-post","status-publish","format-standard","has-post-thumbnail","category-california","tag-california","tag-california-headlines","tag-california-news"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/posts\/409871","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/comments?post=409871"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/posts\/409871\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/media\/409872"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/media?parent=409871"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/categories?post=409871"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us-ca\/wp-json\/wp\/v2\/tags?post=409871"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}