- 2.2 million vehicles susceptible to Bluetooth-based attack in California
- The vulnerability is due to the security systems installed by the dealer.
- Researchers at the University of California, San Diego discovered that all security devices built by Acrisure depend on the same secure key.
A vulnerability has been found in the KARR and SWDS car security systems manufactured by Acrisure that allow remote control via Bluetooth. The vehicles had security systems installed by car dealers in California, specifically such as anti-theft and tracking devices. However, thanks to this trick, it seems that the vehicles can be unlocked and give the attacker more control.
Researchers at the University of California, San Diego found that all 2.2 million cars were purchased from Southern California dealerships since 2017, although the secondary market means the vehicles could be elsewhere in the U.S., and even as far away as Japan.
Worryingly, investigators also found a publicly accessible database containing information on all vehicles with the security system equipped.
Latest videos ofTechnologyRadar
How Bluetooth controls these cars
Look
Investigators determined that the cars were purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver’s side window, with the anti-theft device mounted under the dashboard.
Use is simple: a mobile app connects to the KARR security system via Bluetooth and includes functions such as locking and unlocking doors, controlling the horn and flashing the headlights. It can also prevent the car from starting, although this only works if it is not already running.
The problem is with the implementation, which researchers found depended on the same secure key in KARR’s security systems. Once decrypted, all cars equipped with the same device were believed to be open to attack.
Changing the secure key is not an option, nor is turning off Bluetooth. Of particular concern is that researchers found that even if the buyer does not pay a subscription for the KARR app and system, the hardware is still in place. Worse yet, you have the same access to the vehicle’s doors, ignition, horn, and headlights.
“Removing the devices is not trivial,” UCSD compsci doctoral candidate and paper co-author Yibo Wei said in the report on the research (to be published in full in August). “You have to open the dashboard, cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”
The patch is in
Jerry Yu, also a co-author, wrote: “Instead of breaking a window to gain access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle and have it unlock the car doors.”
KARR has told media that only vehicles installed “with certain Bluetooth-related components” are affected and the company has released a firmware update.
Follow TechRadar on Google News and add us as a preferred source to receive news, reviews and opinions from our experts in your feeds.




