- UCSD researchers discovered a severe vulnerability in aftermarket KARR car alarms, installed in over 2 million vehicles across the US, allowing Bluetooth-based hacking.
- The flaw enables attackers to unlock cars, disable ignition, honk horns, flash lights, or even strand drivers, all via a universal authentication key shared across all KARR devices.
- KARR alarms are typically installed by car dealers without buyers' knowledge or consent, often remaining in vehicles even if the owner declines to purchase the feature.
- The company Acrisure Protection Group released a firmware update after 18 months, but owners must manually patch via the KARR app, and many are unaware they have the device.
- The vulnerability poses significant risks for car theft, tracking, and sabotage, with researchers finding 97 affected vehicles in a 20-minute scan near UC San Diego.
- A single authentication key extracted from the KARR app allows any attacker with a custom app to control any nearby KARR-enabled vehicle.