2.2 Million Cars Have a Bluetooth Flaw That Lets Thieves Unlock Them

Suspicious-figure-by-parked-car-at-night breaking in
Suspicious-figure-by-parked-car-at-night
Suspicious-figure-by-parked-car-at-night breaking in
Suspicious-figure-by-parked-car-at-night

At least 2.2 million cars on American roads carry a hidden anti-theft device that computer scientists at the University of California San Diego say can be hijacked over Bluetooth, letting an attacker lock and unlock the doors and immobilize the engine from up to five yards away. The devices were sold by dealerships as a paid upgrade meant to prevent theft. Instead, researchers found, they opened a new door for it.

The vulnerable hardware is a small unit installed under the dashboard on the driver’s side, paired with a smartphone app that dealerships use to manage vehicle inventory and, later, that owners can use to lock and unlock their car, honk the horn, flash the headlights, or immobilize the engine while it is parked. Most of the affected cars were sold new at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and today. Used cars move across state lines and internationally, and researchers say several hundred thousand of the vulnerable vehicles have already turned up throughout the rest of the United States, in Canada, and as far away as Japan.

How the Flaw Works

The device, sold under the brand names KARR and SWDS, relies on a single cryptographic key shared across every unit the manufacturer has ever made. Once the UC San Diego team cracked that one key, they had the means to access every car equipped with the device. Aaron Schulman, a professor in the university’s Department of Computer Science and Engineering and one of the study’s senior authors, compared it to a company shipping every lock in a product line pre-set to the same four-digit code, with no way for an owner to change it.

Jerry Yu, who earned his master’s degree in the same department and co-authored the paper, said the practical risk is plain to see. Instead of smashing a window to get into a car, a thief can connect to the device over Bluetooth from a short distance, unlock the doors remotely, and then use tools already common among locksmiths to start the engine and drive away. No broken glass, no alarm, and in many cases no sign of forced entry at all, which can complicate insurance claims after the fact.

Researchers also found that public databases store location data tied to vehicles running these devices, meaning an attacker could in theory identify and track a specific car before ever approaching it. The team is deliberately withholding the technical details of how they reverse-engineered the encryption so the method cannot be copied by criminals. They plan to present the full findings at the DEF CON security conference in Las Vegas on August 9 and at the USENIX Security conference in Baltimore on August 12.

A second manufacturer, Rockledge, makes similar Bluetooth-based devices that researchers found may also be vulnerable, though the attack is harder to pull off. Exploiting a Rockledge unit would require an attacker to be physically present when a driver uses the system, recording the digital handshake between phone and device, then replaying it later to gain access. Researchers said Rockledge had not responded to their disclosure as of publication, so that vulnerability remains unconfirmed by the manufacturer.

How Owners Can Check Their Car

Many vehicles equipped with the affected device display a small sticker reading “KARR” or “SWDS” on the driver’s side window, and the hardware itself is typically visible as a button or unit mounted underneath the dashboard. Drivers who bought a car new from one of the affected brands in Southern California anytime from 2017 to today, or who bought a used car that originated there, should check for either marking. The device remains active and exploitable regardless of whether the original buyer ever activated the companion app or paid for the ongoing service.

Acrisure, the company behind the KARR and SWDS brand, released a firmware update on July 20 addressing the vulnerability. The fix is not automatic. Owners have to download the KARR app and apply the update themselves, and the company has posted instructions at www.KARRsecurity.com. Simply removing the device is not a practical option for most owners. Researchers note that the hardware is wired directly into a vehicle’s ignition and computer systems, and pulling it out means opening the dashboard and cutting and reconnecting wiring that is woven directly into the car’s electronics, a job few owners are equipped to do safely themselves.

Researchers also recommended a longer-term fix that goes beyond this specific incident: requiring physical interaction, such as pressing a button inside the car, before any new smartphone is allowed to pair with a Bluetooth-based vehicle security system. That single design change would have blocked the exact attack path the UC San Diego team demonstrated. A thief standing outside the car would have no way to complete the pairing process without getting inside first.

An 18-Month Wait for a Fix

Reporting on the disclosure timeline shows Acrisure, the parent company behind the KARR and SWDS brand, first learned of the vulnerability from researchers in January 2025. The firmware patch addressing it was not released until July 20, 2026, a gap of roughly a year and a half between notification and a public fix. Neither the researchers’ published paper nor Acrisure’s own statements explain what caused that delay, but the lag left millions of vehicles exposed for well over a year after the company already knew the risk existed.

This is not the first time Bluetooth has opened a back door into a modern car. Security researchers demonstrated in 2015 that a Jeep Cherokee could be taken over and driven remotely from more than 10 miles away using nothing but a laptop, a stunt that led to a recall of 1.4 million vehicles. More recently, a separate flaw dubbed PerfektBlue, found in the widely used BlueSDK Bluetooth software stack made by OpenSynergy, was shown capable of exposing infotainment systems in Mercedes-Benz, Volkswagen and Skoda vehicles to remote code execution. Automotive security researchers describe the KARR and SWDS case as part of a broader pattern: aftermarket and dealer-installed hardware often sits outside the security review processes automakers apply to their own factory-built systems, yet the added hardware gets the same physical access to a car’s ignition and locks.

A Decade-Long Trail

The discovery traces back to 2018, when a separate UC San Diego research group led by then-Ph.D. student Nishant Bhaskar was hunting for Bluetooth fingerprints belonging to credit card skimmers, the small devices criminals plant inside gas pumps to steal payment card data. In the course of that unrelated work, the team noticed Bluetooth signals they could not identify. Years of follow-up research eventually traced those signals to the Acrisure and Rockledge devices, and the team then set out to test whether the underlying security held up. It did not.

The research was backed in part by a National Science Foundation grant, and the team disclosed its findings to NHTSA, Acrisure and Rockledge ahead of the public release, giving manufacturers a window to prepare a fix before the vulnerability became public knowledge.

What This Means for Buyers

The discovery adds a new item to the list of things worth checking on any used car, alongside a title history and an odometer check. A car that looks perfectly secure, with an intact alarm system and no signs of tampering, can still be exposed if it carries one of these devices and the firmware has never been updated. Buyers shopping for a used vehicle that originated in Southern California, in particular, have reason to ask a dealer or seller directly whether the car has ever had a KARR or SWDS system installed, and to confirm the July 20 update has been applied before assuming the vehicle is secure.

The episode is also a reminder that anti-theft technology sold as an upgrade is not automatically safer than no device at all. A locked car with an intact window is a known, well-understood barrier. A locked car with a hidden Bluetooth backdoor is a risk most owners never knew existed until a research team happened to stumble across it while looking for something else entirely.


Sources:

Jarrod

Jarrod Partridge is the founder of Motoring Chronicle and an FIA accredited journalist with over 30 years of experience following motorsport and the global automotive industry. A member of the AIPS International Sports Press Association, Jarrod has covered Formula 1 races and automotive events at venues around the world, bringing first-hand insight to every race report, car review, and industry analysis he writes. His work spans the full breadth of motoring — from the latest EV launches and road car reviews to the cutting edge of motorsport competition.

Leave a Comment

More in News

Cars left in muddy field at airport

Airport Meet and Greet Parking Lost Its Safety Badge After Cars Were Left in Fields

Jill Gale booked a last-minute flight to Montenegro from Bristol ...
Close up of hand filling up car with fuel at a UK fuel station.

Diesel Hits £100 a Tank Again as Prices Jump 17p in Less Than a Month

Diesel drivers filling up a standard 55-litre family car are ...
Pothole and Moving Car

Road Damage Caused 71 Breakdowns Every Day in 2025 and 2026 Is Already Looking Worse

Road damage caused 71 breakdowns every single day in Britain ...

Trending on Motoring Chronicle

Cadillac Goddess Sculpture – GM global headquarters

How GM Design put history and innovation at the heart of General Motors’ new global headquarters

General Motors’ new global headquarters at Hudson’s Detroit isn’t simply ...
Wheel clamp

What Happens When the Clamp Team Finds Your Untaxed Car (and How to Avoid It)

More than 498,000 vehicles on UK roads are currently untaxed, ...
Parking ticket under wind screen wiper of a car

Brighton Drivers Face £70 Fines as Western Road Becomes a Red Route This Summer

Drivers who use one of Brighton's busiest shopping streets need ...

Ford Recalls 177,000 Mustangs, Explorers and Lincolns Over Three Defects

Ford Motor Company has filed three separate recalls covering more ...

UK Airports Now Charge Up to £1.60 a Minute to Drop Off a Passenger

Pulling up outside a UK airport to drop off a ...