Cyber Security

How a dealer-installed security system left two million cars open to thieves

Researchers at UC San Diego discovered a Bluetooth flaw in KARR and SWDS car security systems affecting 2.2 million vehicles. Learn how to secure your car.
How a dealer-installed security system left two million cars open to thieves

I recently spent an afternoon in a suburban shopping center with a handheld spectrum analyzer and a smartphone running a specialized Bluetooth discovery app. Most people see a sea of glass and steel when they look at a parking lot. I see a chaotic mesh of Bluetooth Low Energy (BLE) advertisements. Among the usual fitness trackers and wireless headphones, I noticed a recurring ID string that did not match any standard consumer electronics. From a risk perspective, this is the digital equivalent of finding an unmarked, locked door in a public hallway. You do not know what is behind it, but you know it probably shouldn't be there.

This curiosity is what led researchers at the University of California San Diego (UCSD) to uncover a vulnerability that affects over 2.2 million vehicles. The architectural paradox is stark. Dealerships sell these aftermarket systems to provide peace of mind and theft prevention. In reality, the hardware introduces a systemic vulnerability that allows a malicious actor with a common smartphone to unlock doors or disable an engine from five yards away. The expected security model is a shield for the owner. The actual exploitability is a master key for an attacker.

The shadow hardware hiding in your steering column

Many vehicle owners are unaware that their cars contain these modules. The devices in question are KARR Security Systems and SWDS modules manufactured by Acrisure. These are not factory components installed by Ford, Toyota, or Honda. Instead, dealerships install them as inventory management tools. These modules allow dealers to track cars on the lot and ensure they stay secure before a sale. When a customer buys the car, the dealer often tries to sell the system as a premium anti-theft add-on.

If the customer declines the upgrade, the dealer does not usually remove the hardware. It is a cost-intensive process that requires significant dashboard disassembly and modifications to the ignition wiring. Consequently, the module remains active but dormant in the dashboard. The researchers found that even when a customer refuses the service, the Bluetooth radio continues to broadcast. This creates a pervasive attack surface that the owner does not even know exists. A vehicle with a "KARR" or "SWDS" sticker on the window is the primary indicator of this hidden hardware.

A master key for two million digital locks

The vulnerability is a classic failure of cryptographic implementation. At the architectural level, every KARR and SWDS device uses the identical cryptographic key for Bluetooth authentication. In the world of information security, this is a cardinal sin. It is the equivalent of a hotel chain using the same physical master key for every guest room door in every city. Once an attacker recovers the key from one device, they have the key for all 2.2 million devices.

The UCSD researchers reverse-engineered the system to extract this shared key. With this secret in hand, they built a tool that allows any Bluetooth-enabled device to authenticate as a legitimate user. The attack is stealthy because it does not require a complex exploit chain or a zero-day in the phone's operating system. It simply uses the protocol exactly as it was designed, but with a compromised credential that should have been unique to each car. An attacker within range can remotely unlock the doors, flash the headlights, or sound the horn. More importantly, they can trigger the "starter kill" feature. While they cannot start the car and drive it away using this flaw alone, they can effectively brick the vehicle or gain easy physical access to the interior to perform a mechanical theft.

The accidental discovery of a systemic risk

The path to this discovery began in 2018 during a completely different project. The UCSD team was scanning gas stations for Bluetooth-enabled credit-card skimmers. These skimmers allow criminals to harvest card data from pump card readers and retrieve it wirelessly. During these scans, the researchers kept seeing the same unidentified BLE beacons in parking lots. Their curiosity turned into a multi-year forensic investigation into the source of these signals.

They eventually traced the signals to the KARR and SWDS modules. Proactively speaking, the team spent years verifying the scope of the problem before going public. They identified that the affected vehicles are primarily concentrated in Southern California but are now spread across the United States, Canada, and Japan due to the secondary car market. This highlights the long-tail risk of aftermarket automotive hardware. When a car is resold, the new owner has no idea they are inheriting a vulnerable, dealer-installed radio module.

Tracking vehicles through public data leaks

The threat is not limited to proximity attacks. During the investigation, the researchers found that publicly accessible databases expose location information for many vehicles equipped with these systems. This turns a random opportunity into a targeted operation. A malicious actor could potentially cross-reference these databases to identify the precise location of a specific vehicle.

From an end-user perspective, this is a gross violation of privacy. The system that was marketed as a way to protect the vehicle is actually a beacon that broadcasts its position to the internet. This is a common issue with "connected" aftermarket devices. They are often built with a focus on functionality and low cost, while security and data integrity are treated as secondary concerns. The database leak means an attacker does not have to drive around looking for KARR stickers. They can simply download a list of targets and plan their route.

Replay attacks and the Rockledge modules

The researchers also examined similar systems from a competitor called Rockledge. While the KARR systems suffer from the shared key issue, the Rockledge systems appear vulnerable to a replay attack. In this scenario, an attacker intercepts the legitimate Bluetooth signal sent from the owner's phone to the car. They record that signal and play it back later to perform the same action.

This type of attack is like a digital tape recorder. If the communication is not protected by "rolling codes" or time-sensitive tokens, the car cannot tell the difference between the original command and the recording. Rockledge has not yet responded to the researchers' findings. This lack of communication makes it difficult to validate the extent of the vulnerability, but it serves as a warning for anyone using similar smartphone-controlled vehicle systems.

Practical steps for vehicle owners

Acrisure released a firmware update on July 20, 2026, to address the shared key vulnerability. This is a positive step, but the deployment of the patch is problematic. Unlike a modern Tesla or a smartphone, these modules do not always support seamless over-the-air updates. Owners must use the KARR mobile app to push the update to the hardware in their dashboard.

If you own a vehicle purchased from a dealership in the last nine years, you should check for the presence of these systems. Look for stickers on the driver-side window or a small plastic module with an LED light tucked under the dashboard near the steering column. Patching as a method of plugging holes in a ship's hull is only effective if the crew knows the hull is leaking. Many owners will never hear about this vulnerability and will continue to drive vulnerable vehicles for years.

Key takeaways for consumers

  • Verify your hardware: Check your purchase agreement or look for KARR/SWDS branding on your windows or key fobs.
  • Update the firmware: If you have the KARR app, ensure you are running the latest version and follow the prompts to update the vehicle module.
  • Request removal or disabling: If you do not use the anti-theft features, ask a trusted mechanic if the module can be safely disconnected. Note that this may require rewiring the ignition system.
  • Audit dealer add-ons: When buying a new or used car, specifically ask about aftermarket tracking or security modules and request their removal if you do not want them.

From a risk perspective, the safest configuration is a smaller attack surface. Every additional radio and every third-party module is a potential entry point for an attacker. In the case of KARR and SWDS, the very thing meant to keep the car safe became its greatest weakness.

Sources:

  • NIST National Vulnerability Database (NVD)
  • UC San Diego Department of Computer Science and Engineering Research Papers
  • USENIX Security Symposium Proceedings 2026
  • DEF CON 34 Presentation Materials
  • National Highway Traffic Safety Administration (NHTSA) Safety Disclosures

Disclaimer: This article is for informational and educational purposes only. It does not replace a professional cybersecurity audit or official guidance from vehicle manufacturers and authorized service centers.

bg
bg
bg

See you on the other side.

Our end-to-end encrypted email and cloud storage solution provides the most powerful means of secure data exchange, ensuring the safety and privacy of your data.

/ Create a free account