← News·MarketsMarkets

KARR Bluetooth flaw leaves 2.2 million vehicles open to unauthorized access, patch issued July 20

Computer security researchers at the University of California San Diego disclosed a Bluetooth vulnerability in dealer-installed KARR and Southwest Dealer Services security modules affecting at least 2.2 million…

NM
NewsMV Markets Desk
3 min read
31 July 2026Markets desk
Share this dispatch

Computer security researchers at the University of California San Diego disclosed a Bluetooth vulnerability in dealer-installed KARR and Southwest Dealer Services security modules affecting at least 2.2 million vehicles. Acrisure released a firmware patch on July 20, 2026, one day before public disclosure. Owners must apply it through the official KARR Security app; updating a phone or a vehicle infotainment system does not reach the separate module.

What the flaw allows

The affected devices rely on a shared secret authentication key used across every unit. Once UC San Diego researchers recovered that key, they could send commands that any vulnerable KARR device would accept. An attacker standing within about five yards of a parked car can lock or unlock the doors, silence the alarm, sound the horn, flash the headlights, or prevent the vehicle from starting.

The researchers found no method to start the engine remotely or shut down a car already in motion. That boundary matters, but unlocking the doors gives a thief a foothold to use separate tools to create or program a key. The devices also broadcast recognizable Bluetooth Low Energy signals, and historical databases containing those signals could reveal where a particular vehicle has regularly parked or traveled.

Scope of exposure

KARR and Southwest Dealer Services products appear under several names: KARR Security, KARR Fusion, KARR BT, KARR S.W.A.T. and S.W.A.T. Dealer. The company works with more than 3,000 dealerships nationwide. UC San Diego found the modules most often in vehicles sold through Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California since 2017.

Make and model cannot confirm or rule out exposure. The device is dealer-installed aftermarket hardware, and some dealers left it connected even when buyers declined the service, meaning a driver might carry a vulnerable module with no active KARR account and no knowledge of the hardware inside the car.

Applying the patch

KARR Security, in a statement provided to CyberGuy, described the vulnerability as "highly complex" and said it presents a low risk under real-world conditions. The company said it has no confirmed reports of the flaw being exploited. Owners with an active KARR account can push the firmware update through the KARR Security app after logging in; owners of non-active systems can complete the same process using the last eight digits of their VIN as a validation step.

KARR customer support is reachable at 800-395-5277 for cases where the app cannot locate the vehicle or finish the update. Owners who want the module physically removed should use the original dealership or a qualified automotive electrical technician, as the hardware connects to the ignition system and pulling the wrong wire can stop the car from starting. The July 20, 2026 patch date is the reference point for confirming update status through the app.

Categoryenergy

Filed via foxnews.com

Keep reading

More from the markets desk

Key takeaways

Frequently asked

Which vehicles are affected by the KARR Bluetooth flaw?

At least 2.2 million vehicles with dealer-installed KARR or Southwest Dealer Services modules are affected, most often found in Honda, Toyota, Mazda, Ford and Jeep vehicles sold through Southern California dealerships since 2017. Make and model alone cannot confirm or rule out exposure because the hardware is aftermarket and dealer-installed.

How do I install the patch?

Owners apply the firmware update through the KARR Security app after logging in; those with non-active systems can complete the same process using the last eight digits of their VIN as a validation step. Updating a phone or vehicle infotainment system does not update the separate module.

What can an attacker do with this vulnerability?

An attacker within about five yards of a parked car can lock or unlock the doors, silence the alarm, sound the horn, flash the headlights, or prevent the vehicle from starting. They cannot start the engine remotely or shut down a car already in motion.

What if the app cannot find my vehicle or finish the update?

Owners can reach KARR customer support at 800-395-5277. To have the module physically removed, use the original dealership or a qualified automotive electrical technician, since the hardware connects to the ignition system and pulling the wrong wire can stop the car from starting.