A security flaw affecting an aftermarket anti theft device installed in more than two million vehicles has put Bluetooth security in modern cars back in the news.
Popular Science reported that researchers from the University of California, San Diego found they could exploit a weakness in the KARR Security System, a device installed by many dealerships, to unlock doors, flash headlights, sound the horn and stop a vehicle from starting if its engine was already switched off.
The device was originally sold to dealerships as an anti theft tool, making the discovery an ironic one. Researchers found they could communicate with the system over Bluetooth using a custom built application, turning a security feature into a way of gaining access to a vehicle.
KARR Security said it has not seen criminals use the vulnerability to steal cars. The company also released a firmware update on 20 July after learning about the issue from researchers in January 2025.
“Researchers at UC San Diego identified a vulnerability affecting BLE based auto theft devices, including a small percentage of KARR devices with certain Bluetooth related components,” KARR Security told Popular Science. “The vulnerability described in the research is highly complex and presents a low risk to customers under real world conditions.”
The company added, “Nevertheless, we responded promptly and developed a firmware update to address the issue.”
How Does The Bluetooth Hijack Work?
According to Popular Science, the vulnerability comes down to one authentication key shared across every KARR device. Once researchers gained access to one unit, they could communicate with any other device using that same key.
The attack does not let someone start a vehicle using only a phone. Researchers showed that an intruder could unlock the doors over Bluetooth and then use locksmith key cloning tools available online to extract a key from the vehicle’s computer before starting the engine.
Jerry Yu, who worked on the research at the University of California, San Diego, said, “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth device inside the vehicle, and make it unlock car doors.”
Stefan Savage, a computer science professor at the University of California, San Diego, told Wired that the KARR flaw is “probably the worst” car hacking threat he has seen.
Who Could Be At Risk?
Many drivers may not even know the device is installed because Popular Science reported that dealerships often fitted the KARR Security System before selling vehicles and then offered buyers access to its features as a paid extra. Drivers who declined the service often kept the hardware installed inside the vehicle.
That means many owners may have a vulnerable device connected to their car without ever using it. Anyone who bought a used vehicle during the past nine years could also have inherited the system without realising it.
More from Cybersecurity
- Fake Claude Desktop Ads Hit 29 Organisations With Data-Stealing Malware
- How AI Slop Is Forcing GitHub To Close Its Doors
- Are Home Routers Europe’s Most Dangerous Cyber Vulnerability?
- Why Are Businesses Still Paying Ransoms If Hackers Keep Demanding More?
- Can Software Developers Still Trust Their Own Vulnerability Scanners?
- AI Has Stopped Just Assisting Hackers And Now It’s Running The Attacks
- What Does The New European Cyber Evaluation Plan Mean For Software Vendors?
- The Most Active Ransomware Group: Who Are The Gentlemen?
Aaron Schulman, senior author of the research from the University of California, San Diego Department of Computer Science and Engineering, said, “Many car owners don’t even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study.”
Drivers can look for a KARR or SWDS sticker on the driver’s side window or a small blinking button beneath the dashboard. Anyone with an active KARR account can install the latest firmware through the company’s app. Owners who never activated the service can also update the device using the app and the last eight digits of the vehicle identification number.
KARR Security told Popular Science, “Active customers may apply the update directly from their phone after securely logging in to the KARR Security app. Vehicle owners of non active systems can still update via the app using their VIN (last 8 digits) as a validation step.”
Schulman also suggested every affected owner should install the update, saying, “This update needs to be installed even if you are a vehicle owner who didn’t activate the system when you bought your car at the dealership.”
Have We Seen Bluetooth Security Flaws Before?
The findings bring back memories of a guide Kaspersky wrote in August last year after researchers disclosed a different Bluetooth vulnerability called PerfektBlue.
That research examined infotainment systems using OpenSynergy Blue SDK software, which Kaspersky said is installed in around 350 million vehicles from manufacturers including Ford, Mercedes Benz, Skoda and Volkswagen.
According to Kaspersky, attackers would first need to pair a device over Bluetooth. If successful, they could send malicious commands to the infotainment system. Depending on the vehicle’s electronic design, this could allow access to information such as contacts stored in the head unit, vehicle location and microphone audio. Kaspersky also explained that, in certain vehicle architectures, access to the CAN bus could theoretically allow someone to interfere with functions such as braking.
The guide explained that most cars ask drivers to approve new Bluetooth connections, making unexpected pairing requests worth treating carefully. Kaspersky also advised owners to install the latest firmware supplied through manufacturers and dealerships because software updates released by OpenSynergy first need to reach car makers before they can reach drivers. Another option is to switch off in car Bluetooth when it is not needed.
Bluetooth attacks against cars are rare, but these two pieces of research tell us that wireless connections deserve the same care as any other connected device. Regular software updates and making sure to decline unexpected Bluetooth pairing requests are good ways for drivers to keep their vehicles protected.
