UC San Diego computer science professor Aaron Schulman and researcher Nishant Bhaskar found that every KARR anti-theft alarm shares the same Bluetooth authentication key, exposing an estimated 2.2 million vehicles across Southern California to unlock, ignition-kill and horn-honk commands from anyone within Bluetooth range. “This is one of the biggest vulnerabilities of a Bluetooth device that has ever happened in terms of scale,” Schulman said.
KARR is a dealer-installed add-on sold through Southwest Dealer Services, a unit of the insurer Acrisure. Dealerships across Southern California have wired it into cars since 2017, typically upselling it for $300 to $800 at signing. Buyers who decline the ongoing subscription often keep the hardware anyway, and Acrisure estimates about half of owners do not know their car has it installed at all. The affected lots span Honda, Toyota, Mazda, Ford and Jeep dealerships in the region.
The flaw surfaced when the researchers reverse-engineered the KARR smartphone app’s Bluetooth traffic and traced a single hardcoded authentication key built into every unit, which Schulman compared to “using ‘1234’ as your passcode.” Anyone within range can issue the same commands as the owner’s own phone: lock or unlock the doors, sound the horn (including while the car is moving), disable the alarm, or immobilize the ignition.
Schulman and Bhaskar first discovered the weakness in 2018 while researching card-skimming devices, then formally disclosed it to Acrisure in January 2025. Acrisure shipped a firmware patch on July 20, 2026, roughly 18 months later, timed ahead of planned public presentations of the research at DEF CON and the USENIX Security Symposium. Acrisure has described the real-world risk as low.
The patch does not push automatically. Owners need to download the KARR Security app and follow its update steps to receive it. To check whether a car has the hardware at all, look for a “KARR” or “SWDS” sticker on the windows.
USA