KARR Bluetooth Vulnerability Exposes More Than Two Million Car Security Systems

Researchers at the University of California, San Diego, identified vulnerabilities in the KARR Security System, an aftermarket vehicle security product

KARR Bluetooth Vulnerability Exposes More Than Two Million Car Security Systems
Vulnerabilities

Illustrative image generated with AI

Unauthenticated radio commands with no visible indication

Researchers at the University of California, San Diego, identified vulnerabilities in the KARR Security System, an aftermarket vehicle security product estimated to be installed in more than 2 million vehicles across the United States.

An attacker within Bluetooth range of a vehicle can communicate with the device and send commands without being detected. No attacks have been linked to specific groups or campaigns.

The research was made public on August 5, 2026.

From unlocking to vehicle immobilization

The exposed functions go beyond the alarm system. An attacker can:

  • silently unlock the vehicle;
  • disable the security system;
  • activate the horn;
  • flash the lights;
  • disable the ignition.

The last action may prevent the driver from starting or operating the vehicle. The risk therefore combines logical access to the vehicle, neutralization of its security system, and potential immobilization.

The exact versions of the KARR Security System affected have not been disclosed. No CVE identifiers or CVSS score have been reported.

How to identify affected vehicles

The most immediate indicator is a “KARR” sticker affixed to the driver-side window. Its presence suggests that owners should check the system’s status and whether an update is available.

It is not known whether all installed devices share the same configuration or are vulnerable in the same way.

System update as the primary mitigation

Owners should contact KARR or the system installer to request that the device be patched. An update procedure is shown in the final part of the video accompanying the research, starting at 19:10.

A firmware update through a mobile app has also been suggested, but this method has not been confirmed as an official procedure. In the absence of verified instructions, owners should rely on the manufacturer or an authorized installer.

Read next

Sources

This article is an original reworking based on the sources below.

Back to home

Latest Cybersecurity News

All cybersecurity news →