2.2 Million Cars Have a Bluetooth Flaw That Lets Thieves Unlock Them
At least 2.2 million cars on American roads carry a hidden anti-theft device that computer scientists at the University of California San Diego say can be hijacked over Bluetooth, letting an attacker lock and unlock the doors and immobilize the engine from up to five yards away. The devices were sold by dealerships as a paid upgrade meant to prevent theft. Instead, researchers found, they opened a new door for it.
The vulnerable hardware is a small unit installed under the dashboard on the driver’s side, paired with a smartphone app that dealerships use to manage vehicle inventory and, later, that owners can use to lock and unlock their car, honk the horn, flash the headlights, or immobilize the engine while it is parked. Most of the affected cars were sold new at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and today. Used cars move across state lines and internationally, and researchers say several hundred thousand of the vulnerable vehicles have already turned up throughout the rest of the United States, in Canada, and as far away as Japan.
How the Flaw Works
The device, sold under the brand names KARR and SWDS, relies on a single cryptographic key shared across every unit the manufacturer has ever made. Once the UC San Diego team cracked that one key, they had the means to access every car equipped with the device. Aaron Schulman, a professor in the university’s Department of Computer Science and Engineering and one of the study’s senior authors, compared it to a company shipping every lock in a product line pre-set to the same four-digit code, with no way for an owner to change it.
Jerry Yu, who earned his master’s degree in the same department and co-authored the paper, said the practical risk is plain to see. Instead of smashing a window to get into a car, a thief can connect to the device over Bluetooth from a short distance, unlock the doors remotely, and then use tools already common among locksmiths to start the engine and drive away. No broken glass, no alarm, and in many cases no sign of forced entry at all, which can complicate insurance claims after the fact.
Researchers also found that public databases store location data tied to vehicles running these devices, meaning an attacker could in theory identify and track a specific car before ever approaching it. The team is deliberately withholding the technical details of how they reverse-engineered the encryption so the method cannot be copied by criminals. They plan to present the full findings at the DEF CON security conference in Las Vegas on August 9 and at the USENIX Security conference in Baltimore on August 12.
A second manufacturer, Rockledge, makes similar Bluetooth-based devices that researchers found may also be vulnerable, though the attack is harder to pull off. Exploiting a Rockledge unit would require an attacker to be physically present when a driver uses the system, recording the digital handshake between phone and device, then replaying it later to gain access. Researchers said Rockledge had not responded to their disclosure as of publication, so that vulnerability remains unconfirmed by the manufacturer.
How Owners Can Check Their Car
Many vehicles equipped with the affected device display a small sticker reading “KARR” or “SWDS” on the driver’s side window, and the hardware itself is typically visible as a button or unit mounted underneath the dashboard. Drivers who bought a car new from one of the affected brands in Southern California anytime from 2017 to today, or who bought a used car that originated there, should check for either marking. The device remains active and exploitable regardless of whether the original buyer ever activated the companion app or paid for the ongoing service.
Acrisure, the company behind the KARR and SWDS brand, released a firmware update on July 20 addressing the vulnerability. The fix is not automatic. Owners have to download the KARR app and apply the update themselves, and the company has posted instructions at www.KARRsecurity.com. Simply removing the device is not a practical option for most owners. Researchers note that the hardware is wired directly into a vehicle’s ignition and computer systems, and pulling it out means opening the dashboard and cutting and reconnecting wiring that is woven directly into the car’s electronics, a job few owners are equipped to do safely themselves.
Researchers also recommended a longer-term fix that goes beyond this specific incident: requiring physical interaction, such as pressing a button inside the car, before any new smartphone is allowed to pair with a Bluetooth-based vehicle security system. That single design change would have blocked the exact attack path the UC San Diego team demonstrated. A thief standing outside the car would have no way to complete the pairing process without getting inside first.
An 18-Month Wait for a Fix
Reporting on the disclosure timeline shows Acrisure, the parent company behind the KARR and SWDS brand, first learned of the vulnerability from researchers in January 2025. The firmware patch addressing it was not released until July 20, 2026, a gap of roughly a year and a half between notification and a public fix. Neither the researchers’ published paper nor Acrisure’s own statements explain what caused that delay, but the lag left millions of vehicles exposed for well over a year after the company already knew the risk existed.
This is not the first time Bluetooth has opened a back door into a modern car. Security researchers demonstrated in 2015 that a Jeep Cherokee could be taken over and driven remotely from more than 10 miles away using nothing but a laptop, a stunt that led to a recall of 1.4 million vehicles. More recently, a separate flaw dubbed PerfektBlue, found in the widely used BlueSDK Bluetooth software stack made by OpenSynergy, was shown capable of exposing infotainment systems in Mercedes-Benz, Volkswagen and Skoda vehicles to remote code execution. Automotive security researchers describe the KARR and SWDS case as part of a broader pattern: aftermarket and dealer-installed hardware often sits outside the security review processes automakers apply to their own factory-built systems, yet the added hardware gets the same physical access to a car’s ignition and locks.
A Decade-Long Trail
The discovery traces back to 2018, when a separate UC San Diego research group led by then-Ph.D. student Nishant Bhaskar was hunting for Bluetooth fingerprints belonging to credit card skimmers, the small devices criminals plant inside gas pumps to steal payment card data. In the course of that unrelated work, the team noticed Bluetooth signals they could not identify. Years of follow-up research eventually traced those signals to the Acrisure and Rockledge devices, and the team then set out to test whether the underlying security held up. It did not.
The research was backed in part by a National Science Foundation grant, and the team disclosed its findings to NHTSA, Acrisure and Rockledge ahead of the public release, giving manufacturers a window to prepare a fix before the vulnerability became public knowledge.
What This Means for Buyers
The discovery adds a new item to the list of things worth checking on any used car, alongside a title history and an odometer check. A car that looks perfectly secure, with an intact alarm system and no signs of tampering, can still be exposed if it carries one of these devices and the firmware has never been updated. Buyers shopping for a used vehicle that originated in Southern California, in particular, have reason to ask a dealer or seller directly whether the car has ever had a KARR or SWDS system installed, and to confirm the July 20 update has been applied before assuming the vehicle is secure.
The episode is also a reminder that anti-theft technology sold as an upgrade is not automatically safer than no device at all. A locked car with an intact window is a known, well-understood barrier. A locked car with a hidden Bluetooth backdoor is a risk most owners never knew existed until a research team happened to stumble across it while looking for something else entirely.
Sources:
- Computer Scientists: 2M Cars with Anti-Theft Systems Installed by Dealers at Higher Theft Risk
- 2 Million Cars with Anti-Theft Systems Installed by Dealers are at Higher Risk of Theft
- 2 million cars at risk of sneaky Bluetooth hack that unlocks doors
- KARR Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks