- 2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California
- The vulnerability is due to vendor-installed security systems
- Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key
A vulnerability has been found in the KARR and SWDS car security systems manufactured by Acrisure, which enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. However, thanks to this hack, it appears that vehicles can be unlocked, with some additional control given to the attacker.
Researchers at the University of California San Diego found that the 2.2 million cars were purchased from Southern California dealers since 2017, although the secondary market means the vehicles could be elsewhere in the United States, and even as far away as Japan.
Worryingly, the researchers also found a publicly available database of information on all vehicles equipped with the security system.
Latest videos fromTechRadar
How Bluetooth controls these cars
Look at
The investigators determined that the cars were purchased from Honda, Toyota, Mazda, Ford and Jeep dealers, and the affected vehicles have “KARR-SWDS” marked on the driver’s side window with the anti-theft device mounted under the dash.
Use is straightforward: A mobile app connects to the KARR security system via Bluetooth and includes functions such as locking and unlocking doors, controlling the horn and flashing headlights. It can also prevent the car from starting, although this only works if it isn’t already running.
The problem is with the implementation, which the researchers discovered, was based on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device are believed to be open to attack.
Changing the secure key is not an option, nor is disabling Bluetooth. Of particular concern is that researchers found that even if the buyer does not pay for a subscription to the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn and headlights.
“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which was released in full in August). “You have to open the dashboard and cut and connect the wires that are deeply intertwined with the car’s computers and ignition system.”
The patch is in
Jerry Yu, also a co-author, wrote: “Instead of smashing a window to gain access to a vehicle, thieves could simply remotely connect via Bluetooth to the device inside the vehicle and have it unlock the car doors.”
KARR has told the media that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a firmware update.
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



