A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

← Back to the feed

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

Wired · 10 hours ago

Security researchers at UC San Diego have discovered a serious vulnerability in the KARR Security System, an aftermarket car alarm fitted to more than two million vehicles across the United States. The flaw allows anyone within Bluetooth range to remotely unlock a vehicle, disable its alarm, sound the horn, flash the lights, or even cut the ignition and strand the driver. This matters because the device is typically installed by dealerships rather than manufacturers or owners, meaning many drivers are unaware their car contains a hackable component at all, let alone one requiring a manual software update.

According to the UC San Diego team, at least half of affected owners never requested the device, which is usually fitted to deter theft from dealer lots and simply left in place after sale. Drivers can check for its presence via a KARR or "SWDS" (SouthWest Dealer Services) sticker on the driver-side window, or a small blinking button under the dashboard, with Southern California particularly affected due to the alarm's popularity there, though installations have been found nationwide and abroad. Acrisure Protection Group, which sells the KARR system, has released a firmware fix, and owners are urged to update via the KARR Security smartphone app (Android or iOS) under "customer service" and "firmware update".

  • KARR car alarms in 2m+ US vehicles have a serious Bluetooth hack flaw
  • Flaw lets hackers unlock, disable alarms, or immobilise cars remotely
  • Owners must manually check for the device and install a firmware patch

Americas Cybersecurity Research Science Technology World

Read the full article at the source →