A dealer-installed aftermarket alarm can give anyone within Bluetooth range unauthorized control over basic functions in a vulnerable car, according to researchers at the University of California, San Diego. The vendor released a firmware correction on July 21, 2026. The researchers estimate that more than 2 million Bluetooth-capable KARR units have been deployed, although the number still running vulnerable software is not known.
The flaw can be used to unlock doors, silence an alarm, disable the ignition, trigger the horn or flash the lights. It does not let an attacker remotely start the engine or steer a moving vehicle. That boundary limits the exploit, but an unlocked and quiet car gives a thief physical access without breaking glass or immediately attracting attention.
KARR alarms are commonly fitted by dealerships to protect inventory before sale. The hardware often stays in place after a buyer declines to pay for the alarm service. Owners can therefore inherit a radio-equipped module they did not order, cannot see easily and may never encounter in the vehicle’s factory documentation.
One Shared Key Lets a Nearby Phone Issue Commands
The vulnerable model uses a shared authentication secret rather than a unique credential for every unit. UC San Diego researchers located that secret inside the KARR smartphone application while examining its code. They then built their own Android software to reproduce commands that a nearby alarm would accept as legitimate.
The attack requires Bluetooth proximity; the reported flaw is not a direct internet takeover from another city. Radio range still covers parking lots, driveways, streets and traffic queues where a target can be observed. Publicly collected Bluetooth scans can also reveal places where a particular device has appeared repeatedly, giving an attacker a way to identify likely parking locations before approaching the car.
A unit can remain receptive even when the owner did not activate the paid alarm service. Researchers found that the device broadcasts while the vehicle is running and for as long as 10 minutes after shutdown. A radio command can wake the inactive feature, producing only a short horn sound and light flash before additional commands are sent.
Owners May Not Know the Alarm Is Still Broadcasting
The most direct visual clues are a KARR sticker on the driver-side window or an SWDS label associated with SouthWest Dealer Services. Some installations also include a small illuminated button beneath the dashboard. The devices are especially common in Southern California, but the research team detected them in vehicles elsewhere in the United States and abroad.
UC San Diego estimates that at least half of affected owners never requested the device. Used-car sales widen the communication gap because the current driver may have no relationship with the dealership that installed it. Automakers also cannot deliver the repair through a normal factory recall or an over-the-air vehicle update, since KARR is separate aftermarket equipment.
The discovery began with unexplained Bluetooth signals detected near gas stations in 2018. A later examination of the alarm began in 2024, and the researchers identified the shared credential soon afterward. They notified the vendor in January of last year. The firmware release arrived roughly 18 months later, shortly before the findings were due to be presented at Defcon and a Usenix security conference.
The Patch Requires Drivers to Find a Device They Did Not Buy
Drivers who already use the KARR mobile application should receive an update notice. Other owners first need the KARR app for Android or iOS. Pairing the phone with the module exposes a manual update control. The process is not described as automatic, so installing the app alone does not establish that the vulnerable firmware was replaced. That sequence places the final step with the owner even when a dealership chose and installed the hardware.
Acrisure Protection Group, which sells the system, described exploitation as complex and the practical customer risk as low. It said notices would be distributed through the app, its website and dealer communications. Those channels can reach registered customers, but they are less reliable for drivers who declined the service, bought the car used or do not know the module exists.
Risk Centers on Access and Immobilization, Not Remote Driving
The exploit should not be confused with remote control of steering, brakes or acceleration. Its immediate dangers are unauthorized entry, alarm suppression and denial of service through ignition disabling. Once inside, a thief could pair the unlocked access with a separately available locksmith tool that programs a working key through the dashboard, turning one vulnerability into part of a larger theft method.
Scale makes even a proximity-limited weakness difficult to dismiss. An open radio database led the researchers to estimate deployment above 2 million units. During one short drive near the university, their phone detected 97 equipped vehicles in 20 minutes. Those observations do not establish how many cars remain unpatched, but they show why one universal credential creates more exposure than an isolated defect tied to a single vehicle.
The repair campaign will be complete only when vulnerable units stop accepting the old shared key. App downloads and dealer notices are intermediate measures, not proof that firmware changed in the field. A useful public result would report the number of affected devices, completed updates and unreachable owners. Without that accounting, the people least likely to know about the aftermarket alarm remain the same people most likely to miss its security fix.