
More than 2.2 million vehicles equipped with dealer-installed aftermarket anti-theft systems are vulnerable to a Bluetooth attack that could allow thieves to remotely unlock doors and disable engine starts.
The manufacturer behind the affected devices has released a firmware update, but many owners may not know their vehicles contain the hardware.
The findings come from researchers at UC San Diego's Department of Computer Science and Engineering, who will present their work at DEF CON on August 9 and the USENIX Security Symposium on August 12. The researchers said they responsibly disclosed the vulnerability to the affected vendors and the US National Highway Traffic Safety Administration before publication.
Bluetooth flaw unlocks cars
The flaw affects Bluetooth-enabled KARR Security Systems and SWDS modules manufactured by Acrisure. These aftermarket devices are commonly installed by dealerships to manage vehicle inventory before sale and are later marketed to buyers as optional anti-theft and smartphone control systems. Acrisure is an insurance and financial services company that also provides aftermarket automotive security products through dealerships.
Researchers estimate that at least 2.2 million vehicles sold since 2017 are affected, primarily through Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California. However, because many of these vehicles have since been resold, vulnerable cars are now distributed throughout the United States, Canada, and Japan. Vehicles displaying “KARR” or “SWDS” stickers on the driver-side window are likely equipped with the affected hardware.
The vulnerability exists because every KARR-SWDS device uses the same cryptographic key for Bluetooth authentication. After reverse engineering the system, the researchers recovered the shared key, allowing them to authenticate with any vulnerable device from roughly five yards away.
An attacker within Bluetooth range can remotely unlock vehicle doors, flash the headlights, sound the horn, and prevent the engine from starting. Although the flaw does not directly allow the engine to be started, researchers warn that unlocking the vehicle significantly lowers the barrier for theft.
The researchers also found that the Bluetooth modules remain active even when customers decline to purchase the optional security package at the dealership, leaving many owners unaware that the vulnerable hardware is installed in their vehicles.
During the investigation, the team also discovered that publicly accessible databases expose location information associated with some vehicles equipped with these systems, potentially allowing attackers to identify and track targets before attempting an attack.
The researchers additionally examined similar aftermarket systems manufactured by Rockledge and identified what appears to be a replay attack vulnerability. Exploiting that issue would require intercepting legitimate Bluetooth communications between the owner's phone and the vehicle before replaying them. Rockledge had not responded to the researchers' disclosure when the study was published, preventing them from fully validating the findings.
The research originated in 2018 while UC San Diego researchers were scanning for Bluetooth-enabled credit-card skimmers installed in gas pumps. During that project, they discovered previously unidentified Bluetooth devices that were eventually traced to aftermarket automotive security systems, prompting a broader security analysis.
Acrisure released a firmware update on July 20 that addresses the vulnerability. The researchers recommend that owners of vehicles equipped with KARR or SWDS systems install the update through the KARR mobile app, as physically removing the hardware requires significant dashboard disassembly and modifications to wiring integrated with the vehicle's ignition system.







Leave a Reply