A device sold by car dealerships as an anti-theft upgrade is itself a theft vulnerability. Computer scientists at UC San Diego have found that at least 2.2 million U.S. vehicles are exposed to a Bluetooth attack that lets thieves lock and unlock car doors and immobilize engines from about 5 yards away — without touching the car or breaking any glass.
Dealerships install the device to manage vehicle inventory, then typically market it to buyers as a paid security upgrade. But the vulnerability exists whether or not the buyer accepts. If a customer declines, the device stays installed and active — leaving the vehicle exposed to anyone within Bluetooth range.
A 5-yard Bluetooth range and an unlocked door
An adversary can connect to the device via Bluetooth while standing within roughly 5 yards of the parked vehicle. Once connected, they can remotely unlock the doors and immobilize the engine.
“Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle and make it unlock car doors,” said Jerry Yu, a computer science Ph.D. student at UC San Diego and one of the researchers on the study. The attack does not require the thief to have physical access to the car or any prior information about the owner.
The vulnerability stems from the device’s Bluetooth communication is a protocol designed for convenience at close range, not for securing vehicles. A motivated attacker can exploit this without specialized hardware or deep technical expertise.
Declining the upgrade does not make you safe
When a buyer declines the upgrade, the assumption is that the device is no longer relevant to them. The UC San Diego team found that is not the case. The device stays active, continues listening for Bluetooth connections, and the vulnerability remains fully in place.
Acrisure, the company manufacturing the affected devices, released a patch on July 20 — one day before the announcement. The fix requires owners to download an update via an app. Whether affected owners will find and apply it is an open question, especially those who declined the upgrade and may not have the app installed.
“Many car owners don’t even know that their vehicle is vulnerable,” said Aaron Schulman, a professor in UC San Diego’s Department of Computer Science and Engineering and a senior author on the study. “So we wanted to make sure they were aware by publishing this research.”
2.2 million cars, two manufacturers, two conferences
The initial phase of the research identified at least 1.4 million vulnerable vehicles. Further analysis extended that number to at least 2.2 million. Most of the affected cars were sold at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to the present.
A second company, Rockledge, also makes similar devices that have been found to be potentially vulnerable, though harder to attack. Full details will be presented at DEF CON on August 9 in Las Vegas and the USENIX Security conference on August 12 in Baltimore.
The NHTSA reported more than 850,700 vehicles stolen in the U.S. in 2024 — roughly one every 37 seconds. A method that removes the need to physically break into a car raises the stakes for the millions of owners who may not know they are at risk.