Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth
Date:
Mon, 27 Jul 2026 00:05:00 +0000
Description:
Researchers find dealer-installed KARR and SWDS security systems are open to
a Bluetooth-based hack which can remotely unlock doors and stop a vehicle
from starting.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter 2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California The vulnerability is due to dealer-installed security systems Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key A vulnerability has been found in
KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.
Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be
elsewhere in the US, and even as far afield as Japan. Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped. Latest Videos From TechRadar Watch full video here: How Bluetooth controls these cars 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft - YouTube Watch On The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the KARR-SWDS label on the driver-side window, with
the anti-theft device mounted under the dashboard.
Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isnt already running. You may like If you own a Creative Katana V2X speaker, there's something you must
know Yarbo forced to patch mowers after threat to remotely hijack thousands
of devices Industrial robots targeted by malware, which could open them up to hacking
The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.
Changing the secure key isnt an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesnt pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicles doors, ignition, horn, and headlamps. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Removing the devices is not trivial, UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully
released in August). You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the cars computers and ignition system. The patch is in Jerry Yu, also co-author, wrote Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.
KARR has told media outlets that only vehicles installed with certain Bluetooth-related components are affected, and the company has issued a firmware update . Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/experts-warn-2-2-million-cars-could-be- at-risk-of-hijacking-via-bluetooth
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)