Millions of US Cars Vulnerable via Hidden KARR Alarm Device
Original: A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Why This Matters
Dealer-installed aftermarket devices affecting millions of vehicles expose a largely invisible hardware security gap in the automotive industry.
UC San Diego researchers found that the KARR Security System, installed in over 2 million US vehicles by car dealers, contains a severe Bluetooth vulnerability allowing any nearby hacker to unlock, track, or disable a car's ignition. Acrisure Protection Group released a firmware patch on July 21, 2026.
Security researchers at UC San Diego discovered that the KARR Security System — an aftermarket alarm installed by car dealerships in an estimated 2 million US vehicles — contains a critical Bluetooth vulnerability. Any attacker within Bluetooth range can silently send radio commands to unlock the vehicle, disable the alarm, honk the horn, flash lights, or cut ignition power and leave a driver stranded. The devices are wired directly into a vehicle's critical systems.
The alarm is typically installed on dealer lots to deter auto theft, but is rarely removed when the car is sold — even when buyers explicitly decline to pay for the service. UCSD estimates at least half of affected vehicle owners are unaware the device exists under their hood.
"It's designed to make cars more secure, but ultimately it's created a vulnerability that needs to be patched immediately across millions of vehicles," said Aaron Schulman, the UCSD computer science professor who led the research.
Acrisure Protection Group, the company behind KARR, released a firmware update on July 21, 2026. Owners with the KARR Security smartphone app will receive an automatic alert. Those without the app must download it (Android/iOS), connect to their KARR device, and manually trigger the firmware update via the customer service menu.