Millions of California-bought cars can be hijacked via Bluetooth
University of California San Diego researchers say at least 2.2 million vehicles fitted with KARR and SWDS aftermarket security systems could be vulnerable to nearby Bluetooth attacks. An attacker who obtains the shared security key and is within about five yards could unlock doors, sound the horn, flash lights or stop a stationary vehicle from starting, creating a potential theft and disruption risk.
The devices, made by Acrisure and installed by dealers as tracking and anti-theft upgrades, reportedly use the same key across affected units and may remain active even when buyers decline the service. Researchers say most affected cars were bought from Southern California Honda, Toyota, Mazda, Ford and Jeep dealers over the past nine years, though resales may have spread them further; KARR has issued a firmware update but disputes the claim that all devices are affected.
- Shared Bluetooth key may expose 2.2 million dealer-fitted vehicle security systems.
- Nearby attackers could unlock cars or prevent them starting.
- KARR has released an update while disputing the scale.