2.2 Million Cars Have a Bluetooth Flaw That Lets Thieves Unlock Them

Suspicious-figure-by-parked-car-at-night breaking in
Suspicious-figure-by-parked-car-at-night
Suspicious-figure-by-parked-car-at-night breaking in
Suspicious-figure-by-parked-car-at-night

At least 2.2 million cars on American roads carry a hidden anti-theft device that computer scientists at the University of California San Diego say can be hijacked over Bluetooth, letting an attacker lock and unlock the doors and immobilize the engine from up to five yards away. The devices were sold by dealerships as a paid upgrade meant to prevent theft. Instead, researchers found, they opened a new door for it.

The vulnerable hardware is a small unit installed under the dashboard on the driver’s side, paired with a smartphone app that dealerships use to manage vehicle inventory and, later, that owners can use to lock and unlock their car, honk the horn, flash the headlights, or immobilize the engine while it is parked. Most of the affected cars were sold new at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and today. Used cars move across state lines and internationally, and researchers say several hundred thousand of the vulnerable vehicles have already turned up throughout the rest of the United States, in Canada, and as far away as Japan.

How the Flaw Works

The device, sold under the brand names KARR and SWDS, relies on a single cryptographic key shared across every unit the manufacturer has ever made. Once the UC San Diego team cracked that one key, they had the means to access every car equipped with the device. Aaron Schulman, a professor in the university’s Department of Computer Science and Engineering and one of the study’s senior authors, compared it to a company shipping every lock in a product line pre-set to the same four-digit code, with no way for an owner to change it.

Jerry Yu, who earned his master’s degree in the same department and co-authored the paper, said the practical risk is plain to see. Instead of smashing a window to get into a car, a thief can connect to the device over Bluetooth from a short distance, unlock the doors remotely, and then use tools already common among locksmiths to start the engine and drive away. No broken glass, no alarm, and in many cases no sign of forced entry at all, which can complicate insurance claims after the fact.

Researchers also found that public databases store location data tied to vehicles running these devices, meaning an attacker could in theory identify and track a specific car before ever approaching it. The team is deliberately withholding the technical details of how they reverse-engineered the encryption so the method cannot be copied by criminals. They plan to present the full findings at the DEF CON security conference in Las Vegas on August 9 and at the USENIX Security conference in Baltimore on August 12.

A second manufacturer, Rockledge, makes similar Bluetooth-based devices that researchers found may also be vulnerable, though the attack is harder to pull off. Exploiting a Rockledge unit would require an attacker to be physically present when a driver uses the system, recording the digital handshake between phone and device, then replaying it later to gain access. Researchers said Rockledge had not responded to their disclosure as of publication, so that vulnerability remains unconfirmed by the manufacturer.

How Owners Can Check Their Car

Many vehicles equipped with the affected device display a small sticker reading “KARR” or “SWDS” on the driver’s side window, and the hardware itself is typically visible as a button or unit mounted underneath the dashboard. Drivers who bought a car new from one of the affected brands in Southern California anytime from 2017 to today, or who bought a used car that originated there, should check for either marking. The device remains active and exploitable regardless of whether the original buyer ever activated the companion app or paid for the ongoing service.

Acrisure, the company behind the KARR and SWDS brand, released a firmware update on July 20 addressing the vulnerability. The fix is not automatic. Owners have to download the KARR app and apply the update themselves, and the company has posted instructions at www.KARRsecurity.com. Simply removing the device is not a practical option for most owners. Researchers note that the hardware is wired directly into a vehicle’s ignition and computer systems, and pulling it out means opening the dashboard and cutting and reconnecting wiring that is woven directly into the car’s electronics, a job few owners are equipped to do safely themselves.

Researchers also recommended a longer-term fix that goes beyond this specific incident: requiring physical interaction, such as pressing a button inside the car, before any new smartphone is allowed to pair with a Bluetooth-based vehicle security system. That single design change would have blocked the exact attack path the UC San Diego team demonstrated. A thief standing outside the car would have no way to complete the pairing process without getting inside first.

An 18-Month Wait for a Fix

Reporting on the disclosure timeline shows Acrisure, the parent company behind the KARR and SWDS brand, first learned of the vulnerability from researchers in January 2025. The firmware patch addressing it was not released until July 20, 2026, a gap of roughly a year and a half between notification and a public fix. Neither the researchers’ published paper nor Acrisure’s own statements explain what caused that delay, but the lag left millions of vehicles exposed for well over a year after the company already knew the risk existed.

This is not the first time Bluetooth has opened a back door into a modern car. Security researchers demonstrated in 2015 that a Jeep Cherokee could be taken over and driven remotely from more than 10 miles away using nothing but a laptop, a stunt that led to a recall of 1.4 million vehicles. More recently, a separate flaw dubbed PerfektBlue, found in the widely used BlueSDK Bluetooth software stack made by OpenSynergy, was shown capable of exposing infotainment systems in Mercedes-Benz, Volkswagen and Skoda vehicles to remote code execution. Automotive security researchers describe the KARR and SWDS case as part of a broader pattern: aftermarket and dealer-installed hardware often sits outside the security review processes automakers apply to their own factory-built systems, yet the added hardware gets the same physical access to a car’s ignition and locks.

A Decade-Long Trail

The discovery traces back to 2018, when a separate UC San Diego research group led by then-Ph.D. student Nishant Bhaskar was hunting for Bluetooth fingerprints belonging to credit card skimmers, the small devices criminals plant inside gas pumps to steal payment card data. In the course of that unrelated work, the team noticed Bluetooth signals they could not identify. Years of follow-up research eventually traced those signals to the Acrisure and Rockledge devices, and the team then set out to test whether the underlying security held up. It did not.

The research was backed in part by a National Science Foundation grant, and the team disclosed its findings to NHTSA, Acrisure and Rockledge ahead of the public release, giving manufacturers a window to prepare a fix before the vulnerability became public knowledge.

What This Means for Buyers

The discovery adds a new item to the list of things worth checking on any used car, alongside a title history and an odometer check. A car that looks perfectly secure, with an intact alarm system and no signs of tampering, can still be exposed if it carries one of these devices and the firmware has never been updated. Buyers shopping for a used vehicle that originated in Southern California, in particular, have reason to ask a dealer or seller directly whether the car has ever had a KARR or SWDS system installed, and to confirm the July 20 update has been applied before assuming the vehicle is secure.

The episode is also a reminder that anti-theft technology sold as an upgrade is not automatically safer than no device at all. A locked car with an intact window is a known, well-understood barrier. A locked car with a hidden Bluetooth backdoor is a risk most owners never knew existed until a research team happened to stumble across it while looking for something else entirely.


Sources:

Jarrod

Jarrod Partridge is the founder of Motoring Chronicle and an FIA accredited journalist with over 30 years of experience following motorsport and the global automotive industry. A member of the AIPS International Sports Press Association, Jarrod has covered Formula 1 races and automotive events at venues around the world, bringing first-hand insight to every race report, car review, and industry analysis he writes. His work spans the full breadth of motoring — from the latest EV launches and road car reviews to the cutting edge of motorsport competition.

Leave a Comment

More in News

This is a sample document only, featuring payment owned with a red stamp over the balance stating that the payment is delayed until 2027

FCA Pushes £7.5 Billion Car Finance Payout Back to 2027 for Millions

The FCA's £7.5 billion car finance redress scheme, meant to ...

What September’s Record Electric Car Sales Mean for the £3,750 Grant Running Out Early

September's new car market jumped 13.7 percent to 312,891 registrations, ...
smiling woman touching steering wheel while sitting in car

How to Diagnose a Shaking Steering Wheel Before It Costs You a Repair Bill

Where the shaking happens tells you what is wrong: at ...
Manchester, UK - September 23, 2025: Red brick terrace houses line a residential street in Manchester, with cars parked along the curb

Why Car Theft Risk Now Depends on Your Postcode, ONS Data Reveals

ONS figures show vehicle crime fell 11 percent to 312,250 ...
An automatic number plate recognition camera and a decoy surveillance camera on a pole

DVLA Collected £113 Million in Fines as Car Tax Income Rose 8 Percent

The National Audit Office reports that DVLA collected £113 million ...

Trending on Motoring Chronicle

Car crash vehicles ready to be scrapped

Your Car’s Tiny Bump Now Costs £3,699 To Fix. Here’s Why

A car park bump used to cost a few hundred ...
Thick smoke pours from the exhaust pile on a car. Shallow depth of field, focus on the end of the tail pipe. Closeup view.

Scottish Drivers Could Face Tougher Engine Idling Fines as Watchdog Demands Action

Leaving the engine running while you wait outside the school ...
ABS light

What the ABS Warning Light Actually Means (and Whether It’s Safe to Drive)

An ABS light on its own usually means the anti-lock ...
Z62_8068_2

Paws-itive news for dog lovers: Research shows dogs prefer electric cars for stress-free journeys

It’s official – dogs really do feel more relaxed and ...

Ford Recalls 110,626 Mustangs Over Wiper Failures and a Cracking Rear Differential

Ford is recalling 110,626 vehicles across two separate campaigns: 67,842 ...