A critical Bluetooth vulnerability has been identified in the aftermarket KARR Security System, putting around 2.2 million vehicles at risk of unauthorized access. This flaw allows potential attackers to remotely unlock doors, control alarms, and immobilize vehicles.
Discovery of the KARR Security Flaw
Researchers from the University of California, San Diego, have exposed a significant threat posed by dealer-installed hardware like the KARR system. These systems, commonly added by dealerships for vehicle protection, often remain in vehicles even when not activated by buyers.
This situation has led to a substantial number of vehicles emitting Bluetooth signals, creating a security risk without the owners’ awareness. The vulnerability allows attackers within range to send commands to the vehicle’s alarm system, such as unlocking doors or disabling the alarm.
Technical Insights and Risks
The vulnerability stems from a shared authentication key present in all KARR devices. By reverse-engineering the official KARR mobile app, researchers managed to extract this key, creating an Android app that mimics legitimate user access. This app enabled successful attacks on various vehicles, demonstrating the vulnerability’s widespread impact.
While the flaw does not permit remote driving, it significantly eases the process of vehicle theft by allowing silent entry. The vulnerability raises concerns about the privacy of vehicle owners, as the KARR system emits identifiable signals that can be tracked.
Response and Mitigation Strategies
Despite Acrisure Protection Group’s assessment of the attack as complex and low-risk, once the key is known, attacks become straightforward and scalable. However, the integration of KARR systems outside manufacturers’ native frameworks complicates mitigation efforts.
Following responsible disclosure in January 2025, Acrisure released a firmware patch on July 20. Vehicle owners are urged to verify the presence of KARR hardware and update the firmware via the KARR app. For those unable to confirm or update, contacting the dealership or KARR support is recommended.
This incident highlights broader challenges in automotive cybersecurity, as third-party hardware can bypass established security measures, leaving both manufacturers and consumers vulnerable to delays in response.
