Bluetooth flaw in dealer-installed KARR devices puts over two million cars at risk
Researchers at UC San Diego identified a Bluetooth vulnerability in KARR and SWDS aftermarket security modules that could let nearby thieves unlock doors, silence alarms or prevent a car from starting.
University of California San Diego security researchers discovered that a Bluetooth Low Energy weakness in KARR and Southwest Dealer Services (SWDS) aftermarket security devices exposes roughly 2.2 million cars to remote manipulation. The devices, often installed by dealerships for inventory protection, use a single hard-coded authentication key; once recovered, an attacker within about five yards can lock or unlock doors, silence alarms, flash headlights, sound the horn, or block the vehicle from starting.
The exploit cannot start the engine or stop a moving car, but it can give a thief easy entry to use other tools. The flaw is present in vehicles sold through many brands, especially those serviced by Honda, Toyota, Mazda, Ford and Jeep dealers in Southern California, though any make may be affected. KARR Security issued a firmware update on July 20, 2026, which owners can install via the official KARR Security app, even if they never activated the service.
Consumers should look for driver-side window stickers, inspect beneath the dashboard, review purchase paperwork, and contact the original dealer to confirm installation; professional removal is recommended over DIY attempts. The company maintains the risk is low in real-world conditions but urges prompt updating.
Why it matters
A widely deployed Bluetooth flaw could let thieves silently unlock millions of cars, increasing theft risk.
In this story