KARR Bluetooth flaw leaves 2.2 million vehicles open to unauthorized access, patch issued July 20
Computer security researchers at the University of California San Diego disclosed a Bluetooth vulnerability in dealer-installed KARR and Southwest Dealer Services security modules affecting at least 2.2 million…
Computer security researchers at the University of California San Diego disclosed a Bluetooth vulnerability in dealer-installed KARR and Southwest Dealer Services security modules affecting at least 2.2 million vehicles. Acrisure released a firmware patch on July 20, 2026, one day before public disclosure. Owners must apply it through the official KARR Security app; updating a phone or a vehicle infotainment system does not reach the separate module.
What the flaw allows
The affected devices rely on a shared secret authentication key used across every unit. Once UC San Diego researchers recovered that key, they could send commands that any vulnerable KARR device would accept. An attacker standing within about five yards of a parked car can lock or unlock the doors, silence the alarm, sound the horn, flash the headlights, or prevent the vehicle from starting.
The researchers found no method to start the engine remotely or shut down a car already in motion. That boundary matters, but unlocking the doors gives a thief a foothold to use separate tools to create or program a key. The devices also broadcast recognizable Bluetooth Low Energy signals, and historical databases containing those signals could reveal where a particular vehicle has regularly parked or traveled.
Scope of exposure
KARR and Southwest Dealer Services products appear under several names: KARR Security, KARR Fusion, KARR BT, KARR S.W.A.T. and S.W.A.T. Dealer. The company works with more than 3,000 dealerships nationwide. UC San Diego found the modules most often in vehicles sold through Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California since 2017.
Make and model cannot confirm or rule out exposure. The device is dealer-installed aftermarket hardware, and some dealers left it connected even when buyers declined the service, meaning a driver might carry a vulnerable module with no active KARR account and no knowledge of the hardware inside the car.
Applying the patch
KARR Security, in a statement provided to CyberGuy, described the vulnerability as "highly complex" and said it presents a low risk under real-world conditions. The company said it has no confirmed reports of the flaw being exploited. Owners with an active KARR account can push the firmware update through the KARR Security app after logging in; owners of non-active systems can complete the same process using the last eight digits of their VIN as a validation step.
KARR customer support is reachable at 800-395-5277 for cases where the app cannot locate the vehicle or finish the update. Owners who want the module physically removed should use the original dealership or a qualified automotive electrical technician, as the hardware connects to the ignition system and pulling the wrong wire can stop the car from starting. The July 20, 2026 patch date is the reference point for confirming update status through the app.
Filed via foxnews.com