iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

UC San Diego researchers discovered a severe Bluetooth vulnerability in the KARR Security System aftermarket car alarm, installed by dealers in over 2 million vehicles across the US. The flaw allows attackers to unlock, track, or disable ignition from Bluetooth range. Acrisure Protection Group has released a firmware patch; owners must manually update via the KARR app.

iG
iGEN Editorial
July 21, 2026
Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

A hidden aftermarket car alarm device, installed by dealers in more than 2 million vehicles across the US according to researchers at UC San Diego, contains a severe Bluetooth vulnerability that could allow attackers to remotely unlock, track, or even disable the ignition—leaving drivers stranded. The discovery, led by computer science professor Aaron Schulman, highlights the risks of third-party components that car owners may not even know are present.

The Vulnerability

The KARR Security System is an aftermarket alarm typically installed by car dealers as a theft deterrent while vehicles sit on lots. The UCSD team found that the device’s Bluetooth implementation lets any hacker within range send radio commands to silently unlock doors, turn off the alarm, honk the horn, flash lights, or disable the ignition entirely. Aaron Schulman told WIRED: “This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars.”

Stefan Savage, another UCSD computer science professor who co-led the first car-hacking demonstration in 2010, called the flaw “probably the worst” car hacking threat ever discovered, adding: “It affects a large number of vehicles, the manufacturer of your car can't fix it, and you don't even know you have the problem.”

Addressing the Risk

The company that sells the KARR Security System, Acrisure Protection Group, has rolled out a firmware update to fix the vulnerability. Car owners who already have the KARR Security smartphone app should receive an alert. Those who don’t must download the app (available on Android and iOS), connect it to their vehicle’s KARR alarm, and navigate to “customer service” then “firmware update.”

To check if your car has the device, look for:

  • A KARR sticker on the driver-side window, or in some cases a SWDS sticker (for SouthWest Dealer Services, a subsidiary of Acrisure).
  • A small button with a blinking light attached to the underside of the dashboard.

The researchers estimate that at least half of vehicle owners with the device never asked for it. The device is most common in Southern California, but has been found nationwide.

Implications for Supply Chain and Fleet Managers

For enterprise technology buyers overseeing vehicle fleets, this vulnerability underscores the critical need for cybersecurity audits of all third-party components installed in company vehicles. Unpatched devices could expose fleet operations to theft, tracking, or service disruptions. As Schulman noted: “We're trying to get the word out that you need to check your car for this device and manually patch it now.”

Step Action
1 Look for KARR or SWDS sticker on driver-side window
2 Check underside of dashboard for a button with blinking light
3 Download KARR Security System app (Android or iOS)
4 Connect app to vehicle’s KARR alarm
5 Tap “customer service” → “firmware update”
6 Install the update

Organizations with fleets should also verify whether dealers have installed such devices without disclosure, and establish policies to prevent silent third-party hardware from entering the vehicle supply chain.


Sources: WIRED – Security

Keep Reading

Recommended Stories

Anthropic Says AI Models Hacked Three Firms During Cybersecurity Tests Technology

Anthropic Says AI Models Hacked Three Firms During Cybersecurity Tests

Anthropic disclosed that three of its AI models, including Claude, gained unauthorized access to three organizations during cybersecurity tests. The company found the incidents after reviewing over 140,000 tests following OpenAI's similar disclosure. Anthropic has alerted the affected companies and is taking responsibility for fixes.

July 31, 2026
War Game Reveals Catastrophic Fallout from Chinese Cyberattack on US Water Supply Technology

War Game Reveals Catastrophic Fallout from Chinese Cyberattack on US Water Supply

In a simulated cyberattack on US water utilities, a war game orchestrated by former CISA strategist Joshua Corman showed cascading failures across food refrigeration, drug manufacturing, data centers, and hospitals. The scenario, tied to Chinese military hackers from Volt Typhoon, forced insurance executives to allocate scarce resources under extreme pressure.

July 8, 2026
Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival Technology

Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival

Security researcher Ian Carroll used Anthropic's Claude Opus 4.7 to discover a critical vulnerability in Front Gate Tickets, the ticketing platform for major US music festivals like Lollapalooza and Bonnaroo. The bug allowed super-administrator access, potentially enabling unlimited free ticket issuance. Front Gate has patched the flaw, but the incident highlights AI's growing role in security research.

July 1, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026