Researchers found every KARR anti theft device, a dealer installed box most owners don't know they have, uses the same Bluetooth key, letting anyone within five yards unlock or immobilize a car.
A Bluetooth anti-theft device designed to deter car thieves left 2.2 million US vehicles uniformly exposed to a single shared credential, researchers at the University of California, San Diego said this week. Anyone within roughly five yards can now unlock doors, honk the horn, flash the lights, or immobilize a stopped car. No user interaction is required.
The device is the KARR and SWDS line of dealer-installed telematics boxes, made by Acrisure. Most owners never ordered it: dealerships add the unit to the sale as a paid-service upsell, and the box stays powered in the car even when the buyer declines the subscription. The researchers, from the Schulman group at UCSD's Jacobs School of Engineering, found that every KARR and SWDS unit ships with the same Bluetooth "secure" key. Once they reverse-engineered that key, every equipped car became reachable through the same attack. Standard practice in Bluetooth security is per-device keys, unique to each unit, so a stolen credential exposes one device rather than the whole fleet.
The UCSD Today press release puts the affected fleet at 2.2 million US vehicles, up from an initial 1.4 million estimate when the team first disclosed the flaw. Hundreds of thousands of additional units are in use on secondary markets in the US, Canada, and Japan. The vehicles themselves are mostly Hondas, Toyotas, Mazdas, Fords, and Jeeps bought primarily at Southern California dealerships from 2017 through mid-2026, which is why the data concentrates in California even though the underlying vendor flaw is not California-specific.
An attacker has to be within roughly five yards, close enough that the car's Bluetooth radio pairs with a small hardware kit, according to The Register's coverage of the embargoed research. There is no internet relay and no phishing prompt for the owner to accept. The attacker can unlock the doors, start the horn and lights, and disable the engine if the car is stopped, but cannot drive the vehicle away. That is a narrower set of actions than the word "hijacked" implies and matters for how owners should think about the risk.
Acrisure pushed back on the framing. A spokesperson told reporters that "only a small percentage of devices with certain Bluetooth-related components" are affected, a narrower claim than the researchers' "all units share the same key" finding. The two statements are not directly compatible. Whether every KARR and SWDS unit on the road runs the vulnerable Bluetooth stack, or only a subset of hardware revisions, is one of the questions the full USENIX Security paper, due August 12, will need to settle. The San Diego Union-Tribune covered the same UCSD study, confirming the researchers' account is not a single-outlet artifact.
A second vendor, Rockledge, makes similar dealer-installed units. The UCSD team flagged Rockledge as plausibly vulnerable through a different replay-style attack, but had not heard back from the company as of the embargoed writeup. Treat that finding as adjacent, not equivalent to the KARR flaw. The broader class of dealer-installed telematics boxes has surfaced before: Wired reported on a separate hidden-device vulnerability that let a single device be used to track, hack, or disable vehicles, a different attack path but a similar lesson about who owns the risk.
What an owner can do today: Acrisure released a firmware-and-app patch on July 20, the same day the researchers disclosed to NHTSA, the National Highway Traffic Safety Administration. Applying it requires the owner to know the box is in the car in the first place. The unit is identifiable by a small "KARR" or "SWDS" sticker on the driver's-side window. For owners who want a hard fix, the device can be physically removed, though that means cutting and reconnecting wires behind the dashboard, an invasive job for a box most buyers did not request. Disabling Bluetooth in the car's settings is a temporary stopgap until the patch lands, though the car has to be close enough to pair for the attacker to reach it anyway.
The team's DEF CON 34 talk is scheduled for August 9, with the full USENIX paper to follow three days later. The next independent-validation checkpoint is the conference presentation, not the dealership service lane. Until then, the lesson the researchers want to leave is not the patch but the supply chain: a single third-party Bluetooth vendor's oversight became a uniform exposure across millions of cars whose owners had no way to know it was there. The boxes entered the cars through dealer upsells, and the risk and the patch channel both landed on the owner. The fix shipped on July 20. The accounting for who was supposed to catch the shared key in the first place will land at DEF CON.