2.2 Million Cars Have a Bluetooth Flaw That Lets Thieves Unlock Them

Suspicious-figure-by-parked-car-at-night breaking in
Suspicious-figure-by-parked-car-at-night
Suspicious-figure-by-parked-car-at-night breaking in
Suspicious-figure-by-parked-car-at-night

At least 2.2 million cars on American roads carry a hidden anti-theft device that computer scientists at the University of California San Diego say can be hijacked over Bluetooth, letting an attacker lock and unlock the doors and immobilize the engine from up to five yards away. The devices were sold by dealerships as a paid upgrade meant to prevent theft. Instead, researchers found, they opened a new door for it.

The vulnerable hardware is a small unit installed under the dashboard on the driver’s side, paired with a smartphone app that dealerships use to manage vehicle inventory and, later, that owners can use to lock and unlock their car, honk the horn, flash the headlights, or immobilize the engine while it is parked. Most of the affected cars were sold new at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and today. Used cars move across state lines and internationally, and researchers say several hundred thousand of the vulnerable vehicles have already turned up throughout the rest of the United States, in Canada, and as far away as Japan.

How the Flaw Works

The device, sold under the brand names KARR and SWDS, relies on a single cryptographic key shared across every unit the manufacturer has ever made. Once the UC San Diego team cracked that one key, they had the means to access every car equipped with the device. Aaron Schulman, a professor in the university’s Department of Computer Science and Engineering and one of the study’s senior authors, compared it to a company shipping every lock in a product line pre-set to the same four-digit code, with no way for an owner to change it.

Jerry Yu, who earned his master’s degree in the same department and co-authored the paper, said the practical risk is plain to see. Instead of smashing a window to get into a car, a thief can connect to the device over Bluetooth from a short distance, unlock the doors remotely, and then use tools already common among locksmiths to start the engine and drive away. No broken glass, no alarm, and in many cases no sign of forced entry at all, which can complicate insurance claims after the fact.

Researchers also found that public databases store location data tied to vehicles running these devices, meaning an attacker could in theory identify and track a specific car before ever approaching it. The team is deliberately withholding the technical details of how they reverse-engineered the encryption so the method cannot be copied by criminals. They plan to present the full findings at the DEF CON security conference in Las Vegas on August 9 and at the USENIX Security conference in Baltimore on August 12.

A second manufacturer, Rockledge, makes similar Bluetooth-based devices that researchers found may also be vulnerable, though the attack is harder to pull off. Exploiting a Rockledge unit would require an attacker to be physically present when a driver uses the system, recording the digital handshake between phone and device, then replaying it later to gain access. Researchers said Rockledge had not responded to their disclosure as of publication, so that vulnerability remains unconfirmed by the manufacturer.

How Owners Can Check Their Car

Many vehicles equipped with the affected device display a small sticker reading “KARR” or “SWDS” on the driver’s side window, and the hardware itself is typically visible as a button or unit mounted underneath the dashboard. Drivers who bought a car new from one of the affected brands in Southern California anytime from 2017 to today, or who bought a used car that originated there, should check for either marking. The device remains active and exploitable regardless of whether the original buyer ever activated the companion app or paid for the ongoing service.

Acrisure, the company behind the KARR and SWDS brand, released a firmware update on July 20 addressing the vulnerability. The fix is not automatic. Owners have to download the KARR app and apply the update themselves, and the company has posted instructions at www.KARRsecurity.com. Simply removing the device is not a practical option for most owners. Researchers note that the hardware is wired directly into a vehicle’s ignition and computer systems, and pulling it out means opening the dashboard and cutting and reconnecting wiring that is woven directly into the car’s electronics, a job few owners are equipped to do safely themselves.

Researchers also recommended a longer-term fix that goes beyond this specific incident: requiring physical interaction, such as pressing a button inside the car, before any new smartphone is allowed to pair with a Bluetooth-based vehicle security system. That single design change would have blocked the exact attack path the UC San Diego team demonstrated. A thief standing outside the car would have no way to complete the pairing process without getting inside first.

An 18-Month Wait for a Fix

Reporting on the disclosure timeline shows Acrisure, the parent company behind the KARR and SWDS brand, first learned of the vulnerability from researchers in January 2025. The firmware patch addressing it was not released until July 20, 2026, a gap of roughly a year and a half between notification and a public fix. Neither the researchers’ published paper nor Acrisure’s own statements explain what caused that delay, but the lag left millions of vehicles exposed for well over a year after the company already knew the risk existed.

This is not the first time Bluetooth has opened a back door into a modern car. Security researchers demonstrated in 2015 that a Jeep Cherokee could be taken over and driven remotely from more than 10 miles away using nothing but a laptop, a stunt that led to a recall of 1.4 million vehicles. More recently, a separate flaw dubbed PerfektBlue, found in the widely used BlueSDK Bluetooth software stack made by OpenSynergy, was shown capable of exposing infotainment systems in Mercedes-Benz, Volkswagen and Skoda vehicles to remote code execution. Automotive security researchers describe the KARR and SWDS case as part of a broader pattern: aftermarket and dealer-installed hardware often sits outside the security review processes automakers apply to their own factory-built systems, yet the added hardware gets the same physical access to a car’s ignition and locks.

A Decade-Long Trail

The discovery traces back to 2018, when a separate UC San Diego research group led by then-Ph.D. student Nishant Bhaskar was hunting for Bluetooth fingerprints belonging to credit card skimmers, the small devices criminals plant inside gas pumps to steal payment card data. In the course of that unrelated work, the team noticed Bluetooth signals they could not identify. Years of follow-up research eventually traced those signals to the Acrisure and Rockledge devices, and the team then set out to test whether the underlying security held up. It did not.

The research was backed in part by a National Science Foundation grant, and the team disclosed its findings to NHTSA, Acrisure and Rockledge ahead of the public release, giving manufacturers a window to prepare a fix before the vulnerability became public knowledge.

What This Means for Buyers

The discovery adds a new item to the list of things worth checking on any used car, alongside a title history and an odometer check. A car that looks perfectly secure, with an intact alarm system and no signs of tampering, can still be exposed if it carries one of these devices and the firmware has never been updated. Buyers shopping for a used vehicle that originated in Southern California, in particular, have reason to ask a dealer or seller directly whether the car has ever had a KARR or SWDS system installed, and to confirm the July 20 update has been applied before assuming the vehicle is secure.

The episode is also a reminder that anti-theft technology sold as an upgrade is not automatically safer than no device at all. A locked car with an intact window is a known, well-understood barrier. A locked car with a hidden Bluetooth backdoor is a risk most owners never knew existed until a research team happened to stumble across it while looking for something else entirely.


Sources:

Jarrod

Jarrod Partridge is the founder of Motoring Chronicle and an FIA accredited journalist with over 30 years of experience following motorsport and the global automotive industry. A member of the AIPS International Sports Press Association, Jarrod has covered Formula 1 races and automotive events at venues around the world, bringing first-hand insight to every race report, car review, and industry analysis he writes. His work spans the full breadth of motoring — from the latest EV launches and road car reviews to the cutting edge of motorsport competition.

Leave a Comment

More in News

2027 Genesis GV60 Magma

Genesis GV60 Magma Priced From $69,950 With Up to 641 Horsepower

Genesis has priced its first high-performance model at $69,950 before ...
JAECOO 7 and OMODA 7 SHS-P plug-in hybrid SUVs on UTAC Millbrook proving ground

JAECOO 7 SHS-P Hits 828 Miles in UK Range Test, Beating WLTP by 11%

JAECOO 7 SHS-P owners now have proof their plug-in hybrid ...
A GM electric vehicle using bidirectional charging to power a home

Arlington County Plans to Nearly Double Its EV Charging Rates for Drivers

Electric vehicle owners who plug in at Arlington County, Virginia ...

Why Tesla Is Giving Away Free Tires to Fix a Dangerous Cybertruck Wobble

Tesla has confirmed that a foam insert bonded inside Cybertruck ...

Virginia County Launches School Zone Speed Cameras With $100 Fines Starting in August

Drivers in Blacksburg, Virginia, will get a 30-day grace period ...

Trending on Motoring Chronicle

Depositphotos_515002776_L

Why Does My Car AC Smell?

Car AC smells are usually caused by mould, mildew, or bacteria ...
The car pics up speed, the load on the engine, tachometer, dashboard

How Virginia Became the First State to Sentence Speeders to a Car That Cannot Speed

Virginia has switched on a punishment no American state has ...
2026 Audi A6 TFSI sedan – Daytona Grey Metallic

Audi A6 Wins IIHS Top Safety Pick+ Award, Most of Any Luxury Brand

The 2026 Audi A6 has earned a IIHS TOP SAFETY ...
2026 Subaru Wrx Scaled

2026 Subaru WRX brings back the affordable rally-inspired sports sedan

Subaru of America, Inc. announced pricing today on the 2026 ...
Everything You Need To Know About Car Exhaust Systems

Maryland Ends Its 20 Year Emissions Test Exemption This Month

Owners of older cars in Maryland just lost a shortcut ...