Skip to main content

A small blinking button tucked under the driver’s side dashboard of your car could be all that separates a thief from getting inside it, without a key, without breaking a window, and from up to 15 feet away. Millions of American drivers have no idea that button is even there.

The device is called the KARR Security System, an aftermarket anti-theft alarm commonly installed by car dealerships across the country, particularly in Southern California. Sold by Acrisure Protection Group, it’s pitched to dealers as a way to protect vehicles sitting on the lot. Once a car is sold, many buyers either subscribe to the service or opt out. Dealerships commonly install the system as a protective measure for vehicles on their lots before sale, and in many cases the hardware remains in vehicles even when buyers choose not to activate or pay for the service. Owners often don’t know it’s there at all.

What computer scientists at the University of California, San Diego discovered about that device is remarkable, and not in a good way. The same hardware designed to stop thieves may be quietly making it easier for them, thanks to a car Bluetooth hack that anyone with a basic Android phone and the right knowledge could execute.

The Flaw That Affects 2.2 Million Vehicles

At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, according to computer scientists at UC San Diego’s Department of Computer Science and Engineering. Attackers can get access to cars from as far as five yards away.

The root cause is surprisingly simple. According to the UC San Diego researchers, KARR and SWDS security devices manufactured by Acrisure all rely on the same shared authentication key. That universal key is the same across every single unit ever made. Think of it less like a house key and more like a master key that opens every house on the street, and the researchers found it sitting in plain sight inside the official KARR smartphone app.

The vulnerability stems from a universal Bluetooth authentication key that researchers extracted while reverse-engineering the KARR app’s communications protocol. Because the key is shared across all affected devices rather than unique per vehicle, the UC San Diego team built a proof-of-concept Android application that impersonated the legitimate KARR software and successfully sent unauthorized commands to nearby alarms.

The flaw allows attackers within Bluetooth range to issue commands such as locking or unlocking doors, disabling alarms, triggering horns and lights, and even preventing a vehicle from starting. Once a car is unlocked silently through this method, a thief can then use a variety of tools available to locksmiths to start the car and drive away.

There is one clear limit to what the exploit can do: the hack notably doesn’t start the car’s engine, meaning a thief can’t drive off using nothing but their phone. But removing the barrier of having to physically break in is a substantial step toward a successful theft, and security researchers have long understood that silent entry is often the hardest part.

How This Started: A Gas Pump Skimmer Hunt

The discovery didn’t begin as a car security project. The research originated in 2018 while UC San Diego researchers were scanning for Bluetooth-enabled credit-card skimmers installed in gas pumps. During that project, they discovered previously unidentified Bluetooth devices that were eventually traced to aftermarket automotive security systems, prompting a broader security analysis.

That thread led to a full investigation of the KARR system’s architecture, and what researchers found was a design flaw affecting every device in the entire product line. The team is led by Professor Aaron Schulman of the UC San Diego Department of Computer Science and Engineering, whose group has since built out a comprehensive picture of how widely these systems have been deployed, and how easy they are to exploit.

To count the affected vehicles, researchers used data from the WiGLE wireless tracking database to estimate at least 2.2 million deployed units. WiGLE is a crowdsourced database that logs the Bluetooth and Wi-Fi signals detected by volunteers as they move through the world. KARR devices continuously emit their own identifiable Bluetooth signature, making them trackable in the database’s logs.

During field testing, researchers identified 97 vulnerable vehicles within a 20-minute drive of UC San Diego, highlighting the widespread nature of the issue. That’s nearly 100 cars in a single short trip, each one potentially accessible to anyone running the right software on a standard phone.

The ongoing signal broadcast is itself a secondary problem. The KARR system raises a privacy concern by continuously broadcasting identifiable Bluetooth signals, and according to AppleInsider’s 2026 coverage of the research, that broadcast continues for up to 10 minutes after a vehicle is turned off. A persistent, trackable signal tied to a specific device means anyone monitoring nearby Bluetooth traffic could potentially map a vehicle’s movements or pinpoint where it’s regularly parked overnight.

Which Cars Are Most at Risk

Most of the vulnerable vehicles were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to today. If you purchased a car from a dealership in that region during that window, there’s a real possibility your car has a KARR or SWDS device connected beneath the dashboard, whether you agreed to it or not.

Removing the device is not trivial, according to UC San Diego computer science PhD candidate and paper co-author Yibo Wei. “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.” For most drivers, that means the device isn’t going anywhere, and the practical fix has to come from software.

The easiest way to check whether your vehicle has one is to look for a small blinking button on the underside of the driver’s side dashboard. That button is part of the KARR system. If it is installed in your car at the bottom of the dashboard, your car is likely vulnerable to the attack the researchers have discovered. A “KARR” or “SWDS” sticker on the driver’s side window is another common indicator.

If you’re concerned about the broader risk that connected devices pose in modern vehicles, the risks around keyless systems more generally are worth understanding. Keyless ignition systems carry risks of their own, and the KARR flaw shows that aftermarket hardware can introduce entirely new attack surfaces on top of whatever the manufacturer built in.

18 Months to a Car Bluetooth Hack Patch

Acrisure Protection Group reportedly learned of the vulnerability from the researchers in January 2025, but only issued a software patch on July 20, 2026. That’s an 18-month gap between disclosure and fix, during which millions of vehicles remained unprotected.

Acrisure has pushed back on the severity characterization. KARR Security’s statement, as reported by The Register, described the vulnerability as “highly complex” and presenting “a low risk to customers under real-world conditions.” The company also told Popular Science that it has not seen the vulnerability applied in the real world to break into or steal a car. That may be reassuring, but it also reflects the standard lag between a vulnerability being known to researchers and being adopted by criminal actors.

What makes this particular car Bluetooth hack harder to dismiss as purely theoretical is its scalability. Unlike a vulnerability that requires knowing a target vehicle’s specific device ID, the shared key flaw means the same attack works on every single KARR-equipped car within range. Researchers didn’t need to tailor the exploit for each vehicle. One tool, one key, 2.2 million targets.

The UC San Diego team is scheduled to present their full findings at DEF CON on August 9, 2026 in Las Vegas, and at the USENIX Security Symposium on August 12, 2026 in Baltimore, according to AppleInsider’s coverage. These are the two most prominent venues in security research, and their inclusion signals that this is being taken seriously by the broader cybersecurity community.

This work builds on a long tradition at UC San Diego. In 2010, Professor Stefan Savage and colleagues were the first to demonstrate the ability to hack an automobile remotely, including taking control over the engine and brakes and monitoring conversations taking place within the car. The KARR research, led by Professor Aaron Schulman’s group with support from that same department, is the latest chapter in a years-long effort to expose how automotive software lags behind other industries on security.

Read More: What You Should Know Before Purchasing a Car With a Keyless Ignition System

What to Do Now

The patch exists, but it won’t reach your car automatically. Because the KARR system is third-party equipment, automakers cannot deliver fixes through their standard software update process. This is a crucial distinction: no over-the-air update from Honda, Toyota, Ford, Mazda, or Jeep will fix this. The responsibility falls entirely on the vehicle owner.

Vehicle owners are advised to install the KARR Security app, connect it to their vehicle, and apply the firmware update released on July 20, 2026. The update is available through both the iOS and Android versions of the app. If you’re not sure whether the update has been applied, open the app and check for a firmware version update prompt. If you haven’t used the app in a while, or never activated the service to begin with, this requires creating or logging into a KARR account.

If you’re not a KARR subscriber and never activated the device, this is a good time to contact the dealership where you bought the car and ask directly whether a KARR or SWDS unit was installed. The physical check described above, looking for a small blinking button at the bottom of the driver’s side dashboard, takes less than 30 seconds. Given what researchers found in just a 20-minute drive near San Diego, the odds that one of those signals belongs to your car are higher than most drivers would expect.

AI Disclaimer: This article was created with the assistance of AI tools and reviewed by a human editor.