Researchers at the University of California San Diego have uncovered a critical Bluetooth vulnerability in KARR and SWDS automobile security systems manufactured by Acrisure. The flaw could allow attackers to remotely unlock and control up to 2.2 million vehicles sold in California since 2017.

What You Need to Know

All affected KARR and SWDS devices rely on the same secure encryption key, meaning once cracked, every equipped vehicle becomes vulnerable. The hardware remains active even without a subscription to the accompanying mobile app. Removing the device is complicated and requires cutting into the car's wiring. KARR has released a firmware update, but the fix does not address hardware already installed.

How Bluetooth Controls These Cars

The security systems are installed by car dealers as anti-theft and tracking devices. A mobile app connects to the KARR system over Bluetooth, allowing users to lock and unlock doors, control the horn, flash headlamps, and prevent the car from starting. The researchers found that all devices share the same cryptographic key, making it possible to brute force the connection and gain access to any vehicle equipped with the system.

Once compromised, attackers can remotely unlock doors and manipulate basic functions. The system does not allow starting the engine if it is already running, but it can block ignition when the vehicle is off. The researchers also discovered a publicly accessible database containing information about all vehicles with the security system installed.

Scope of the Problem

Vehicles were purchased from dealerships in Southern California representing multiple major brands. The affected cars carry a KARR-SWDS label on the driver-side window, with the anti-theft device mounted under the dashboard. While the concentration is in California, the secondary market means these cars could be anywhere in the United States and even in Japan.

  • Honda vehicles: Affected models sold through Honda dealerships since 2017 are included in the 2.2 million count.
  • Toyota vehicles: Toyota customers also received the KARR-SWDS system as a dealer-installed option.
  • Mazda vehicles: Mazda owners face the same vulnerability without any ability to change the secure key.
  • Ford vehicles: Ford dealerships sold the systems, contributing to the widespread risk.

Jerry Yu, co-author of the study, noted that instead of breaking a window, thieves could simply connect via Bluetooth to unlock the car. The researchers plan to fully release their findings in August.

Why This Matters

This vulnerability highlights a broader security gap in aftermarket and dealer-installed automotive technology. Unlike factory systems that undergo rigorous testing, third-party security devices often lack proper encryption standards. The shared key design means attackers can target any vehicle once they reverse engineer the system, turning a convenience feature into a mass exploitation vector. Vehicle owners who did not subscribe to the service remain unaware that the hardware is still active and accessible. The difficulty of removing the device, as explained by UCSD PhD candidate Yibo Wei, means the risk persists even after a firmware patch. This incident may push regulators to mandate stronger security requirements for aftermarket car electronics, especially those with wireless connectivity.

Response and Recommendations

KARR has acknowledged the issue and issued a firmware update for vehicles with certain Bluetooth-related components. The company directed affected customers to its website for installation instructions. However, the researchers caution that the patch does not change the underlying hardware design. Owners who see the KARR-SWDS label on their window should contact their dealer to verify whether the update has been applied. For those with active subscriptions, the mobile app must be updated. In the long term, the automotive industry may need to reconsider the security of dealer-installed systems that rely on shared keys and outdated Bluetooth implementations.