You treat your phone like a fortress. You update your laptop daily. You don’t skip the security patch. Yet your car—a two-ton computer rolling down the interstate—might have a gaping hole in its digital armor. One that you never asked for. One that someone else installed. And one that lets strangers hack your ride with a Bluetooth signal from a nearby parking spot.

This isn’t sci-fi. It’s happening right now.

Security researchers at UC San Diego have identified a critical flaw in the KARR Security System, an aftermarket anti-theft device. They estimate it’s installed in over 2 million vehicles across the United States. Most owners don’t even know it’s there. And for a long time, they didn’t know they were vulnerable to having their cars unlocked, paralyzed, or hijacked.

The Hidden Device in Your Car’s Dashboard

The KARR system is marketed as a theft deterrent. It’s wired into the vehicle’s sensitive systems—ignition, alarm, lights, horn. It’s usually installed by dealerships on new car lots to prevent inventory loss. Dealership insurance or policy sometimes mandates it.

But when you buy the car, the dealer doesn’t always remove it. Even if you decline the add-on. Even if it’s not on your final invoice. The device stays. Wired deep in the dash. Blinking its faint blue light. Waiting.

Aaron Schulman, a computer science professor at UCSD who led the study, puts it bluntly.

“This is a system added to cars by dealers… it has a severe vulnerability that allows anyone gain access to any of these cars.”

The device was supposed to make your car safer. Instead, it turned your vehicle into an open target.

How Hackers Control Your Car

The vulnerability stems from a single, shared authentication key. All KARR devices use the same key. That means if a hacker finds it once, they can control them all.

UCSD researchers found this key embedded in the code of the official KARR Security smartphone app. Using reverse-engineering tools, they built their own app. They replicated the authentication protocol. And they tested it.

The results were chilling.

With a tap on a screen, a hacker could:
– Unlock a car’s doors from Bluetooth range.
– Silence the alarm.
– Flash the headlights and honk the horn.
– Disable the ignition, leaving the driver stranded on the side of the road.

Stefan Savage, another UCSD professor who wasn’t involved in this specific study but helped pioneer car hacking research, called this “probably the worst” threat discovered to date.

Why? Because the car manufacturer can’t fix it. You don’t know you have it. And you’re disconnected from the supply chain that installed the flawed software. It provides everything a thief needs. It removes every advantage the owner has.

The “Mayhem” Demo

ACRISure Protection Group, the company behind the KARR system, claims the risk is low. They say the vulnerability is complex and unlikely to occur in real-world conditions. They rolled out a firmware update recently. But it took 18 months to release. The researchers warned them in January of last year. The patch came weeks before major security conferences. That’s not “prompt.” That’s reactive.

In the meantime, the risks are tangible.

Researchers demonstrated this for WIRED. They used their custom app to target vehicles with KARR alarms. They showed how a thief could unlock a car at a red light. They showed how to paralyze a parked car so it wouldn’t start. They even built a “mayhem” button into the app. It triggered horns and lights across multiple cars simultaneously. Chaos. In a university parking lot.

The hackers couldn’t start the ignition remotely. But they could get in. Once inside, a common locksmith tool available online can create a key from scratch. Within minutes, the car is gone. Normally, breaking in sets off the alarm. But with KARR’s vulnerability, the alarm stays silent. The thief gets in. Quietly.

How to Check and Patch Your Car

You need to check your car. Now.

Look for a sticker on the driver-side window. It will say KARR. Sometimes it will say “SWDS” for Southwest Dealer Services, a subsidiary of ACRISure. Look under the dashboard for a small device with a blinking light.

If you have it, you need to update the firmware.

ACRISure says users with the KARR Security app installed should see an alert. If you don’t have the app, download it (iOS or Android). Connect it to your car’s device. Go to “customer service.” Select “firmware update.”

It’s not hard. But you have to know it’s there.

And that’s the problem. Half the owners didn’t ask for the device. They don’t know the app exists. They don’t know to check the window. In Southern California, the device is common. Dealers there love it. But researchers have found KARR systems in vehicles across the entire US. Even abroad.

Why This Matters

Nishant Bhaskar, a UCSD researcher, first noticed these Bluetooth signals in 2018. He was scanning for skimmer devices at gas stations. Then he saw them on the highway. Hundreds of them. From different makes. Different models. He looked them up in the FCC database. They were KARR alarms.

It took six years. Six years of signals bouncing off roads, waiting for someone to figure out what they meant. Graduate student Jerry Yu finally cracked it in 2024. He found the universal key. The shared password.

The ease of access is the danger. Another researcher, Yibo Wei, used WiGLE—a crowdsourced database of radio signals—to estimate the scope. Two million devices. That number is conservative. Real scanning shows them everywhere.

During one test, the team drove around the UCSD campus for 20 minutes. They found 97 vulnerable cars. In a small radius. In minutes.

These devices broadcast their location. Hackers can track historical patterns. They can see where you park. Where you live. Where your routine is. It’s a scout’s dream. For a thief, it’s a roadmap.

The Patch Isn’t Enough

The firmware update fixes the authentication flaw. It closes the back door. But the update relies on you taking action. On you noticing a sticker. On you downloading an app you might not even know you need.

The system was designed for security. It failed because it relied on a shared secret in a world of networked devices. A single point of failure. Across millions of cars.

Schulman is right to worry about the pervasiveness. When a dealer installs something by default in every car, the scale is unimaginable. You can’t rely on the manufacturer. They didn’t make it. You can’t rely on the dealer. They probably won’t call you.

You have to protect your own vehicle.

Check the window. Find the device. Update the code.

Because the next time you stop at a light, or leave your car in the garage, or sit in the driveway waiting for a ride… someone with a phone and a Bluetooth connection might be one tap away.