Flaw in 2 million car alarms allows remote vehicle hacking; Bluetooth exploit can unlock cars and kill engines — patch issued after 18 months
Stefan SavageAcrisure Protection GroupKarrUniversity of California, San Diego

Flaw in 2 million car alarms allows remote vehicle hacking; Bluetooth exploit can unlock cars and kill engines — patch issued after 18 months

A vulnerability in KARR's aftermarket car alarm system, affecting over 2 million vehicles, allows hackers to unlock cars and disable engines via Bluetooth. The flaw, identified by UC San Diego researchers, prompted a patch after 18 months, raising concerns about vehicle security and potential theft.

The Drive The Drive+1 source21 July 2026 · 21:27 UTC
CuriousCats Full Story

A serious vulnerability in the KARR Security System, affecting over 2 million vehicles, allows hackers to unlock cars and disable engines via Bluetooth. The flaw, identified by UC San Diego researchers, stems from a shared authentication key across all devices, enabling remote commands.16

The KARR system, typically installed by dealers as a theft prevention measure, remains active even when a car is turned off, with Bluetooth functionality persisting for up to 10 minutes. This means hackers can exploit the system to unlock doors, disable alarms, or even disable the ignition, leaving drivers stranded.

“The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson stated. However, the researchers labeled it “probably the worst” car hacking threat to date, highlighting the potential for theft and sabotage.

KARR was notified of the vulnerability in January 2022 but took 18 months to issue a patch, which was released just before UCSD's presentations at major security conferences. Car owners are advised to check for KARR stickers on their vehicles and update their systems via the KARR Security smartphone app to mitigate risks.

The researchers also noted that the flaw could allow hackers to track the historical locations of vulnerable cars, raising further concerns about vehicle security and privacy.

Key Insight
“UC San Diego researchers discovered the flaw and warned it is 'probably the worst' car hacking threat. Affected cars have a 'KARR' or 'SWDS' sticker on the driver-side window, and owners need to download the app to install the firmware update.”
CuriousCats studied:
1
The DriveThe Drive
“UC San Diego researchers have just discovered a vulnerability in Karr’s system that could allow nefarious actors to send commands over Bluetooth to unlock car doors, disable ignition, and enable all sorts of other chaos.”
The Drive →
2
WIREDWIRED
“a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car's horn or flash its lights, or even disable its ignition and leave a driver stranded.”
WIRED →
Ask CuriousCats
Who discovered the car alarm vulnerability?
What vehicles are affected by this flaw?
Why is this exploit considered a significant threat?
Are firmware updates available for all affected models?
How does this hacking vulnerability compare to past threats?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats