A hidden aftermarket car alarm device, installed by dealers in more than 2 million vehicles across the US according to researchers at UC San Diego, contains a severe Bluetooth vulnerability that could allow attackers to remotely unlock, track, or even disable the ignition—leaving drivers stranded. The discovery, led by computer science professor Aaron Schulman, highlights the risks of third-party components that car owners may not even know are present.
The Vulnerability
The KARR Security System is an aftermarket alarm typically installed by car dealers as a theft deterrent while vehicles sit on lots. The UCSD team found that the device’s Bluetooth implementation lets any hacker within range send radio commands to silently unlock doors, turn off the alarm, honk the horn, flash lights, or disable the ignition entirely. Aaron Schulman told WIRED: “This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars.”
Stefan Savage, another UCSD computer science professor who co-led the first car-hacking demonstration in 2010, called the flaw “probably the worst” car hacking threat ever discovered, adding: “It affects a large number of vehicles, the manufacturer of your car can't fix it, and you don't even know you have the problem.”
Addressing the Risk
The company that sells the KARR Security System, Acrisure Protection Group, has rolled out a firmware update to fix the vulnerability. Car owners who already have the KARR Security smartphone app should receive an alert. Those who don’t must download the app (available on Android and iOS), connect it to their vehicle’s KARR alarm, and navigate to “customer service” then “firmware update.”
To check if your car has the device, look for:
- A KARR sticker on the driver-side window, or in some cases a SWDS sticker (for SouthWest Dealer Services, a subsidiary of Acrisure).
- A small button with a blinking light attached to the underside of the dashboard.
The researchers estimate that at least half of vehicle owners with the device never asked for it. The device is most common in Southern California, but has been found nationwide.
Implications for Supply Chain and Fleet Managers
For enterprise technology buyers overseeing vehicle fleets, this vulnerability underscores the critical need for cybersecurity audits of all third-party components installed in company vehicles. Unpatched devices could expose fleet operations to theft, tracking, or service disruptions. As Schulman noted: “We're trying to get the word out that you need to check your car for this device and manually patch it now.”
| Step | Action |
|---|---|
| 1 | Look for KARR or SWDS sticker on driver-side window |
| 2 | Check underside of dashboard for a button with blinking light |
| 3 | Download KARR Security System app (Android or iOS) |
| 4 | Connect app to vehicle’s KARR alarm |
| 5 | Tap “customer service” → “firmware update” |
| 6 | Install the update |
Organizations with fleets should also verify whether dealers have installed such devices without disclosure, and establish policies to prevent silent third-party hardware from entering the vehicle supply chain.