As modern cars have evolved into multi-ton computers on wheels, drivers are beginning to learn they need to install security updates for their vehicles’ code, just as they would for a phone or laptop. Yet not even the most tech-savvy car owners would expect they’d need to install a patch for an insecure third-party component they never installed or requested—and likely aren’t even aware of—that’s been wired into some of the most sensitive systems of their vehicle, leaving it vulnerable to stealthy hacking, tracking, and even roadside paralysis.
That’s the disturbing discovery of a team of security researchers at UC San Diego, who found that a model of aftermarket car alarm known as the KARR Security System, installed in more than 2 million vehicles across the US by their estimate, can let any hacker within Bluetooth range send radio commands to silently unlock the car at will, turn off its alarm, honk the car’s horn or flash its lights, or even disable its ignition and leave a driver stranded.
The KARR alarm devices are typically installed by car dealers, not manufacturers or owners, and used as a measure to prevent auto theft from dealer lots. Yet when the cars are sold, the alarms typically aren’t removed, even if the buyer declines to pay for it as an additional feature. That means car owners across the US have a hackable device under their hood whose code they’ll need to update to protect their vehicle—but one that, in many cases, they never purchased and have no idea is there.
“This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars,” says Aaron Schulman, the UCSD computer science professor who led the research. “It’s designed to make cars more secure, but ultimately it’s created a vulnerability that needs to be patched immediately across millions vehicles. We’re trying to get the word out that you need to check your car for this device and manually patch it now.”
The company that sells the KARR Security System, Acrisure Protection Group, today rolled out a firmware update for the vulnerable Bluetooth model of its aftermarket KARR alarm to fix the security issues UCSD uncovered. Car owners who already have the KARR Security smartphone app installed should receive an alert about the firmware update, the UCSD team says. Those who don’t have it installed will need to download the KARR Security System smartphone app (Android, iOS), connect it to their vehicle’s KARR alarm, then tap “customer service” and “firmware update.”
Given that at least half of car owners who have the KARR device installed didn’t ask for it to be in their vehicles, according to UCSD’s estimate, you can check if your car has the device by looking for a KARR sticker on your car’s driver-side window—or in some cases a sticker reading, “SWDS” for SouthWest Dealer Services, a subsidiary of Acrisure Protection Group—as well as a small button with a blinking light attached to the underside of your car’s dashboard. Car owners in Southern California are most likely to have the device installed due to its popularity among car dealers in the region, but the UCSD researchers warn that they’ve found the devices installed in vehicles across the US and even in other countries.




