Skip to main content
Emerging ThreatsMalware & Ransomware

Bluetooth Flaw Exposes 2.2 Million Vehicles to Hijacking Risk

Close-up of unlocked car door with smartphone nearby on city street.

"Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors," Jerry Yu, coauthor on the research and a UCSD computer‑science graduate, said in the University of California San Diego's release.

What UC San Diego researchers found

Researchers at the University of California San Diego released an advance look at work showing that dealer‑installed KARR and SWDS security systems manufactured by Acrisure contain a widespread design flaw: "all … rely on the same secure key," the team wrote. With knowledge of that key, a Bluetooth connection and physical proximity of about five yards, an attacker can remotely issue commands that unlock doors, make the horn honk, flash headlights or prevent a stopped vehicle from starting.

The team says the vulnerability was discovered serendipitously while the researchers were studying credit card skimmers and noticed unknown Bluetooth fingerprints. The advance report is published this week; the researchers will present their work at DEF CON on August 9 and at the USENIX Security conference on August 12, when their full writeup will be available.

How KARR and SWDS devices work — and why they persist in cars

KARR and SWDS units are installed by dealerships and marketed as dealer upgrades that provide key‑fob‑like functions and act as antitheft devices. The devices also provide dealer and buyer tracking capability to locate an equipped vehicle in case of theft. According to UCSD, the devices are typically sold as a paid upgrade at dealerships across the United States.

The researchers report that the units remain active even when a buyer declines the paid service, so owners without an active contract can still be exposed. UCSD PhD candidate Yibo Wei explained that removing the devices is not a trivial aftermarket task: owners would have to "open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system."

Scale and spread: at least 2.2 million vehicles and thousands of dealerships

UCSD's advance report estimates at least 2.2 million vehicles are fitted with KARR/SWDS devices vulnerable to the Bluetooth issue. KARR says its products are available through more than 3,000 dealerships nationwide. The researchers identified the largest concentration of affected vehicles as purchases made in Southern California within the past nine years from Honda, Toyota, Mazda, Ford and Jeep dealerships.

The team also noted that secondary‑market resales distribute equipped cars beyond the original sales footprint, putting affected vehicles throughout the United States and even as far away as Japan. The researchers reported discovering a public database that stores information about equipped vehicles, increasing the potential visibility of which cars are fitted with the devices.

KARR's response and its dispute over scope and risk

KARR Security has released a firmware update intended to address the issue; the company says the update can be installed by both active customers and those whose security system contracts are inactive, and that steps for installation are available on the company’s website. KARR told reporters that "only a small percentage of devices 'with certain Bluetooth‑related components' are actually affected" and that "The vulnerability described in the research is highly complex and presents a low risk to customers under real‑world conditions."

At the same time, UCSD's finding that "all KARR‑SWDS devices rely on the same secure key" contrasts with KARR's characterization of the affected subset. KARR added that it "responded promptly and developed a firmware update to address the issue."

How vehicle owners, dealerships, and resellers are confronted by the finding

  • Vehicle owners: If a car was purchased at a dealership in the past nine years — especially from Honda, Toyota, Mazda, Ford or Jeep dealerships in Southern California — owners may have a KARR/SWDS unit installed even if they declined the paid service. Owners should consult KARR's website for firmware update instructions; removal of the hardware is described by UCSD researchers as a complex task because of wiring tied into the car's electronics and ignition.
  • Dealerships: Dealerships are the channel through which KARR/SWDS devices are installed and sold as paid upgrades. The devices' persistence after contract decline and the availability of an over‑the‑air firmware update change the technical and customer‑support decisions dealerships may face when informing buyers.
  • Resellers and used‑car buyers: Secondary‑market resales have distributed equipped vehicles widely. The researchers' discovery of a public database that records equipped vehicles increases the possibility that used‑vehicle listings — and buyers — can identify cars fitted with KARR/SWDS units.

There is a practical patch in place: KARR pushed a firmware update and published steps for installing it. But the UCSD finding that a common secure key underpins the vulnerable install base raises a distinct question of scale: how many cars retain active but little‑known hardware that is difficult to remove and easy to exploit within a few yards? The researchers will lay out technical detail in August; until then, owners of vehicles bought at the identified dealerships and in the specified timeframe have a clear action — check for the device and apply the firmware update described on KARR’s site.

Original story at The Register