KARR's car alarm shared one key across 2.2m cars

UC San Diego researchers found that KARR, an aftermarket alarm installed at dealerships across Southern California, uses one Bluetooth authentication key across all 2.2 million units sold since 2017, letting anyone nearby unlock the car, kill the ignition or sound the horn. Acrisure, which makes KARR, shipped a patch on July 20, 2026, about 18 months after the researchers first reported the flaw. Fixing it requires the owner to install an app update; roughly half of owners do not know the alarm is even in their car.

· 2 min read
KARR's car alarm shared one key across 2.2m cars - photo 1
Tags USA

UC San Diego computer science professor Aaron Schulman and researcher Nishant Bhaskar found that every KARR anti-theft alarm shares the same Bluetooth authentication key, exposing an estimated 2.2 million vehicles across Southern California to unlock, ignition-kill and horn-honk commands from anyone within Bluetooth range. “This is one of the biggest vulnerabilities of a Bluetooth device that has ever happened in terms of scale,” Schulman said.

KARR is a dealer-installed add-on sold through Southwest Dealer Services, a unit of the insurer Acrisure. Dealerships across Southern California have wired it into cars since 2017, typically upselling it for $300 to $800 at signing. Buyers who decline the ongoing subscription often keep the hardware anyway, and Acrisure estimates about half of owners do not know their car has it installed at all. The affected lots span Honda, Toyota, Mazda, Ford and Jeep dealerships in the region.

The flaw surfaced when the researchers reverse-engineered the KARR smartphone app’s Bluetooth traffic and traced a single hardcoded authentication key built into every unit, which Schulman compared to “using ‘1234’ as your passcode.” Anyone within range can issue the same commands as the owner’s own phone: lock or unlock the doors, sound the horn (including while the car is moving), disable the alarm, or immobilize the ignition.

Schulman and Bhaskar first discovered the weakness in 2018 while researching card-skimming devices, then formally disclosed it to Acrisure in January 2025. Acrisure shipped a firmware patch on July 20, 2026, roughly 18 months later, timed ahead of planned public presentations of the research at DEF CON and the USENIX Security Symposium. Acrisure has described the real-world risk as low.

The patch does not push automatically. Owners need to download the KARR Security app and follow its update steps to receive it. To check whether a car has the hardware at all, look for a “KARR” or “SWDS” sticker on the windows.


Share
Related News
Search