KARR Alarm Vulnerability Exposes 2 Million Cars
Millions of vehicles across the United States carry a concealed device meant to guard them against theft. Instead, that device has allowed strangers to open doors, silence alarms, and immobilise engines.
Many owners have no idea a dealership fitted a vulnerable system beneath the bonnet of their car.
What the Researchers Found
Specialists at the University of California, San Diego uncovered a serious flaw in the KARR Security System. By their reckoning, dealers have installed such devices in more than two million American vehicles.
An attacker need only stand near the car, within Bluetooth range. A purpose-built application then lets them unlock doors, disable the alarm, sound the horn, flash the headlights, or block the ignition entirely.
Following that last command, the vehicle will not start. The driver risks being stranded in a car park or at the roadside.
How the Devices Got There
Neither manufacturers nor owners install KARR systems. Dealerships do.
The units help protect cars from theft while they sit on the seller’s lot. After a sale, however, the alarm frequently stays in place. That remains true even when the buyer declines to pay for the optional feature.
Consequently, a device wired into critical systems remains inside the vehicle, and the owner may never suspect it exists. Researchers estimate that at least half of drivers with KARR hardware never asked for it.
A Single Key for Every Device
The root cause proved disarmingly simple. One shared authentication key served every vulnerable unit.
Researchers located that key inside the code of the KARR mobile application. They then reconstructed the command exchange protocol and wrote their own program. Any nearby system accepted commands transmitted through it as entirely legitimate.
Dormant Does Not Mean Silent
Even a deactivated alarm keeps transmitting and receiving signals while the vehicle runs, and for up to ten minutes after the engine stops.
An attacker can therefore activate the device remotely, then issue whatever command they wish. In some cases the car emits a brief chirp and light flash. Owners of a paid and already active system would notice nothing unusual at all.
From Unlocked Door to Stolen Car
The flaw cannot start an engine on its own. Nevertheless, the path afterwards is short.
Once the doors stand open, a thief can attach a commercially available device to the diagnostic port and forge a working key within minutes.
Ordinarily, entry would require smashing a window or forcing a door, with every risk of triggering the alarm. The KARR flaw permits an almost invisible entrance instead.
Persistent Identifiers Aid Surveillance
The devices also broadcast constant Bluetooth identifiers. Records of those signals can find their way into public databases and reveal where a vehicle habitually sits.
A prospective thief thus gains the ability to establish a target’s usual parking place well in advance.
How to Check and Patch
Acrisure Protection Group, which sells the KARR Security System, has released a firmware update.
Owners with the KARR application already installed should receive a notification. Everyone else must install the app, connect to the alarm, and trigger the update manually through the customer service section.
Identifying the hardware is straightforward enough. Look for a KARR sticker on the driver’s window, an SWDS sticker, or a small button with a blinking indicator beneath the dashboard. Southern California hosts the greatest concentration, yet researchers found the systems throughout the United States and beyond its borders.
A Disputed Assessment
The developer characterised the attack as complex and judged the real-world risk to be low.
The remedy nonetheless arrived a full eighteen months after the company first received notice of the flaw. Researchers demonstrated that commands could be sent from an ordinary telephone. During a single brief drive near a university campus, they identified ninety-seven vehicles carrying vulnerable devices.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.