- UC San Diego researchers have discovered a vulnerability in KARR's system that could allow nefarious actors to send commands over Bluetooth to unlock car doors, disable ignition, and enable all sorts of other chaos.
- The researchers notified KARR about the vulnerability in January last year, but it took 18 months for the company to issue a firmware update.
- KARR has now issued a firmware update to fix the security issues uncovered by UCSD, just before the Defcon and Usenix conferences.
- Researchers warn drivers to patch their systems and provide instructions for checking and updating the KARR alarm.
- The KARR Security System is installed in over 2 million vehicles across the US, allowing hackers within Bluetooth range to unlock cars and disable ignition.
- KARR devices remain active for up to 10 minutes after a car is turned off, increasing the risk of unauthorized access.
- Stefan Savage, a UCSD researcher, described the vulnerability as 'probably the worst' car hacking threat to date, highlighting the significant risk of theft.
A serious vulnerability in the KARR Security System, affecting over 2 million vehicles, allows hackers to unlock cars and disable engines via Bluetooth. The flaw, identified by UC San Diego researchers, stems from a shared authentication key across all devices, enabling remote commands.16
The KARR system, typically installed by dealers as a theft prevention measure, remains active even when a car is turned off, with Bluetooth functionality persisting for up to 10 minutes. This means hackers can exploit the system to unlock doors, disable alarms, or even disable the ignition, leaving drivers stranded.
“The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions,” a KARR spokesperson stated. However, the researchers labeled it “probably the worst” car hacking threat to date, highlighting the potential for theft and sabotage.

KARR was notified of the vulnerability in January 2022 but took 18 months to issue a patch, which was released just before UCSD's presentations at major security conferences. Car owners are advised to check for KARR stickers on their vehicles and update their systems via the KARR Security smartphone app to mitigate risks.
The researchers also noted that the flaw could allow hackers to track the historical locations of vulnerable cars, raising further concerns about vehicle security and privacy.
“UC San Diego researchers discovered the flaw and warned it is 'probably the worst' car hacking threat. Affected cars have a 'KARR' or 'SWDS' sticker on the driver-side window, and owners need to download the app to install the firmware update.”
