iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Werner Enterprises Posts Highest Revenue Per Truck Growth in One-Way Segment in a Decade CMA CGM and Stonepeak Launch United Ports LLC in $2.4 Billion Terminal Joint Venture UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout Werner Enterprises Posts Highest Revenue Per Truck Growth in One-Way Segment in a Decade CMA CGM and Stonepeak Launch United Ports LLC in $2.4 Billion Terminal Joint Venture UPS shift away from Amazon shows bigger payoff Lanesurf: 62% of Loads Get Vetted Carrier Offers Before Brokers Arrive India-China Border Trade Via Lipulekh Resumes Aug 1; China Permits 20 Traders Geopolitics Drives CMA CGM Q2 Profit Surge of 42% as Volumes and Rates Climb Benchmark Diesel Price Rises Third Week as Futures Plunge; Spread Hits Record Indian Government Limits Sugar Dealers to 400 Tonnes Stock Until November to Curb Hoarding Tenants signing longer leases for larger warehouses as 3PLs lock in capacity US stock market flat as S&P 500 and Dow barely move, Nasdaq slides over 1% on chip rout
Home ›› Technology ›› Cybersecurity ›› Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

UC San Diego researchers discovered a severe Bluetooth vulnerability in the KARR Security System aftermarket car alarm, installed by dealers in over 2 million vehicles across the US. The flaw allows attackers to unlock, track, or disable ignition from Bluetooth range. Acrisure Protection Group has released a firmware patch; owners must manually update via the KARR app.

iG
iGEN Editorial
July 21, 2026
Hidden Car Alarm Device in Millions of US Vehicles Is a Hacking Risk – Patch Now

A hidden aftermarket car alarm device, installed by dealers in more than 2 million vehicles across the US according to researchers at UC San Diego, contains a severe Bluetooth vulnerability that could allow attackers to remotely unlock, track, or even disable the ignition—leaving drivers stranded. The discovery, led by computer science professor Aaron Schulman, highlights the risks of third-party components that car owners may not even know are present.

The Vulnerability

The KARR Security System is an aftermarket alarm typically installed by car dealers as a theft deterrent while vehicles sit on lots. The UCSD team found that the device’s Bluetooth implementation lets any hacker within range send radio commands to silently unlock doors, turn off the alarm, honk the horn, flash lights, or disable the ignition entirely. Aaron Schulman told WIRED: “This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars.”

Stefan Savage, another UCSD computer science professor who co-led the first car-hacking demonstration in 2010, called the flaw “probably the worst” car hacking threat ever discovered, adding: “It affects a large number of vehicles, the manufacturer of your car can't fix it, and you don't even know you have the problem.”

Addressing the Risk

The company that sells the KARR Security System, Acrisure Protection Group, has rolled out a firmware update to fix the vulnerability. Car owners who already have the KARR Security smartphone app should receive an alert. Those who don’t must download the app (available on Android and iOS), connect it to their vehicle’s KARR alarm, and navigate to “customer service” then “firmware update.”

To check if your car has the device, look for:

  • A KARR sticker on the driver-side window, or in some cases a SWDS sticker (for SouthWest Dealer Services, a subsidiary of Acrisure).
  • A small button with a blinking light attached to the underside of the dashboard.

The researchers estimate that at least half of vehicle owners with the device never asked for it. The device is most common in Southern California, but has been found nationwide.

Implications for Supply Chain and Fleet Managers

For enterprise technology buyers overseeing vehicle fleets, this vulnerability underscores the critical need for cybersecurity audits of all third-party components installed in company vehicles. Unpatched devices could expose fleet operations to theft, tracking, or service disruptions. As Schulman noted: “We're trying to get the word out that you need to check your car for this device and manually patch it now.”

Step Action
1 Look for KARR or SWDS sticker on driver-side window
2 Check underside of dashboard for a button with blinking light
3 Download KARR Security System app (Android or iOS)
4 Connect app to vehicle’s KARR alarm
5 Tap “customer service” → “firmware update”
6 Install the update

Organizations with fleets should also verify whether dealers have installed such devices without disclosure, and establish policies to prevent silent third-party hardware from entering the vehicle supply chain.


Sources: WIRED – Security

Keep Reading

Recommended Stories

War Game Reveals Catastrophic Fallout from Chinese Cyberattack on US Water Supply Technology

War Game Reveals Catastrophic Fallout from Chinese Cyberattack on US Water Supply

In a simulated cyberattack on US water utilities, a war game orchestrated by former CISA strategist Joshua Corman showed cascading failures across food refrigeration, drug manufacturing, data centers, and hospitals. The scenario, tied to Chinese military hackers from Volt Typhoon, forced insurance executives to allocate scarce resources under extreme pressure.

July 8, 2026
Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival Technology

Claude AI Helped Hacker Find Way to Free Tickets for Any US Music Festival

Security researcher Ian Carroll used Anthropic's Claude Opus 4.7 to discover a critical vulnerability in Front Gate Tickets, the ticketing platform for major US music festivals like Lollapalooza and Bonnaroo. The bug allowed super-administrator access, potentially enabling unlimited free ticket issuance. Front Gate has patched the flaw, but the incident highlights AI's growing role in security research.

July 1, 2026
Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations Technology

Oracle Warns of Critical PeopleSoft Vulnerability Exploited by ShinyHunters, Affecting Hundreds of Organizations

Oracle has issued a security advisory for a critical remote code execution vulnerability (CVE-2026-35273, CVSS 9.8) in PeopleSoft versions 8.61 and 8.62. The extortion group ShinyHunters is exploiting it, claiming to have breached over 100 organizations and exfiltrated data from ~300 instances. Google's Mandiant reported zero-day exploitation between May 27 and June 9, 2026, and alerted over 100 potentially vulnerable entities.

June 15, 2026
Linux Kernel Vulnerability: A Single Character Threat Technology

Linux Kernel Vulnerability: A Single Character Threat

A logic inversion bug in the Linux kernel, identified as CVE-2026-23111, allows privilege escalation, affecting major distributions like Debian, Ubuntu, and RHEL. The vulnerability highlights challenges in managing AI-driven bug reports.

June 9, 2026