Search Everything in One Place

Explore the web, images, videos, news, and more – all in one place.

News

Two million cars with anti-theft systems installed by dealers are at higher risk of theft

Two million cars with anti-theft systems installed by dealers are at higher risk of theft
This button is part of the KARR system. If it is installed in your car at the bottom of the dashboard, your car is likely vulnerable to the attack the researchers have discovered. Credit: David Baillot/University of California San Diego/Jacobs School of Engineering

At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, computer scientists at the University of California San Diego have found.

At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, computer scientists at the University of California San Diego have found.

Subscribe to our newsletter for the latest sci-tech news updates.

Attackers can gain access to cars from as far as 5 yards (4.6 meters) away. Most of the vulnerable vehicles were bought at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California from 2017 to today.

But because these vehicles are resold on the secondhand market, several hundred thousand vulnerable vehicles can also be found throughout the United States, Canada and even as far as Japan. Many vulnerable cars display a sticker with the word "KARR" or "SWDS" on the driver's-side window.

The vulnerability is due to a device controlled via a smartphone app that is typically installed by dealerships to manage vehicle inventory and prevent theft. The device, installed beneath the dashboard on the driver's side, connects the vehicle and app via Bluetooth.

The app makes the device perform functions similar to a key fob: lock and unlock doors, honk a horn and flash headlights as a warning. In addition, the device can prevent the car from starting as long as the car isn't already running.

All KARR-SWDS devices rely on the same secure key—meaning that once the researchers cracked that key, they had access to all the cars equipped with these devices. It's a bit like setting all passwords for a line of devices to 1234 and making it impossible to change the password.

When a dealership sells a vehicle, it markets the device and app as a paid upgrade—an anti-theft tool as well as a tool to control the car via an app. Even if the buyer declines the upgrade, the device remains active, still leaving the vehicle vulnerable to an attacker in certain situations.

The company manufacturing these devices, Acrisure, released a patch to fix the vulnerability on July 20, 2026. The fix requires downloading an app.

"Many car owners don't even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study," said Aaron Schulman, a professor in the UC San Diego Department of Computer Science and Engineering and one of the study's senior authors.

The vulnerability could allow thieves to steal cars more easily. "Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors," said Jerry Yu, a computer science Ph.D. student in Schulman's research group at UC San Diego and the paper's co-first author.

Once the car is unlocked, attackers can use a variety of tools available to locksmiths to start the car and drive away.

The researchers, led by Schulman, will detail how they discovered the vulnerability and reverse-engineered it at the DEF CON conference Aug. 9, 2026, in Las Vegas and at the the USENIX Security conference Aug. 12 in Baltimore, Maryland.

In the study, researchers identified at least 1.4 million vulnerable vehicles, but further analysis by the UC San Diego researchers increased that number to at least 2.2 million.

Different levels of vulnerability

In addition to Acrisure, Rockledge, a car security and insurance company, makes similar devices. The researchers found these devices may also be vulnerable but are more difficult to attack. An attacker would need to be present when a driver uses these systems to intercept and record their digital interactions, then play those interactions back to gain access to the user's vehicle.

Researchers were unable, however, to validate these findings with Rockledge because the company had not yet responded to the researchers' disclosure as of this writing.

The research team is careful not to disclose details of how they reverse-engineered the systems so their work can't be replicated by thieves. Researchers also disclosed the vulnerabilities to all relevant manufacturers and vendors, as well as to the National Highway Traffic Safety Administration.

How to fix the vulnerability?

"Removing the devices is not trivial. You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car's computers and ignition system," said Yibo Wei, who is also a computer science Ph.D. student in Schulman's group at UC San Diego and the paper's co-first author.

To fix the vulnerability noninvasively, the device firmware—the software that controls the hardware—needs to be updated. On July 20, KARR-SWDS maker Acrisure announced that it had released a firmware update to fix the issue. The update must be made by the vehicle owner via the KARR app. For more information, visit www.KARRsecurity.com.

But to truly make sure similar vulnerabilities do not occur in the future, researchers suggest that physical interaction—like pressing a button inside a car—be required when a new smartphone connects with these Bluetooth-based security systems.

How did the researchers discover the vulnerability?

It all started in 2018 when researchers led by former UC San Diego computer science Ph.D. student Nishant Baskar found Bluetooth fingerprints they didn't recognize while hunting for devices called credit card skimmers, which criminals install in gas pumps to steal consumer credit and debit card data.

After a fair bit of research, they were able to connect the Bluetooth fingerprints to devices manufactured by Acrisure and Rockledge. They then set out to test whether the devices were secure as part of a broader research effort to understand cybersecurity in Bluetooth devices.

Researchers also found that public databases store location information about vehicles equipped with these devices. This, in turn, would allow attackers to track specific vehicles they want to break into.

Provided by University of California - San Diego

This story was originally published on Tech Xplore.
Read full story on Tech Xplore

Related News

More stories you might be interested in.

Common plastic additive makes stretchable OLED displays brighter and more elastic
Tech Xplore·4 hours ago

Common plastic additive makes stretchable OLED displays brighter and more elastic

The same class of chemical additive that makes plastic wrap pliable and vinyl flooring soft could be the key to unlocking the next generation of wearable displays. Researchers at the University of Chicago Pritzker School of Molecular Engineering (UChicago PME) have discovered that blending a common plastic softener into light-emitting polymer films makes those films both brighter and more stretchable.

Ford's new remote kill switch isn't really about stopping car thieves. It's about owning the off switch.
The Auto Wire·1 day ago

Ford's new remote kill switch isn't really about stopping car thieves. It's about owning the off switch.

Ford wants you picturing a thief. Someone jimmies open your F-150, leaves your own key on the seat, and floors it down the interstate while you stand on the curb reaching for your phone. That's the scenario in every headline about Ford's expanded Start Inhibit feature this month, and it's a real scenario the technology solves. It's also the least interesting part of the story. Garage-worthy EDC gear, on sale this week. The more interesting fact...

OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup
Reuters·3 hours ago

OpenAI says AI models went rogue during testing, triggering 'unprecedented' breach at startup

July 21 (Reuters) - OpenAI said on Tuesday that some of its AI models went rogue during a security test and triggered a hack that compromised the infrastructure of AI startup Hugging Face last week. In a blog post, OpenAI said it was testing the capabilities of some of its most advanced models in a controlled environment but that they managed to escape containment, reach the internet, and break

Top