Updated
Updated · WIRED · Jul 21
Acrisure Patches KARR Flaw in 2 Million Cars as Hidden Dealer Alarms Expose Bluetooth Hacking
Updated
Updated · WIRED · Jul 21

Acrisure Patches KARR Flaw in 2 Million Cars as Hidden Dealer Alarms Expose Bluetooth Hacking

3 articles · Updated · WIRED · Jul 21

Summary

  • Acrisure Protection Group released a firmware update for the Bluetooth-enabled KARR Security System after UC San Diego researchers found the dealer-installed alarm could be abused in more than 2 million vehicles.
  • A single authentication key shared across all devices let anyone within Bluetooth range spoof commands to unlock doors, silence alarms, flash lights, honk horns, or disable ignition and strand drivers.
  • Owners must patch the device themselves through the KARR smartphone app; many may not know they have it because dealers often leave the alarm installed even when buyers decline to pay for it.
  • 18 months passed between UCSD's disclosure and the fix, and researchers said the devices can also aid tracking through their Bluetooth signatures, with scans finding 97 KARR-equipped cars in 20 minutes near campus.
  • The case highlights a broader automotive supply-chain risk: the vulnerable component was added by dealerships, not carmakers, leaving affected drivers outside normal recall and update channels.

Insights

Your car may have a vulnerable device you never bought. Who is liable when 'security' add-ons create new risks?
Why did a security firm take 18 months to fix a flaw that lets hackers strand or steal cars?
A single key unlocks two million cars. Is your dealer-installed alarm a hidden backdoor for thieves?

KARR Security System Vulnerability: 2 Million Cars Exposed, Patch Delays, and What Owners Must Do

Overview

In July 2026, a major vulnerability was discovered in the KARR Security System, an advanced anti-theft upgrade installed in about 2 million US vehicles. After UCSD researchers publicly disclosed the flaw, KARR Security quickly released critical firmware updates to address the issue and maintain vehicle protection. The update process is clearly outlined for both activated and non-activated systems, ensuring all affected owners can secure their vehicles. This incident highlights the importance of timely firmware updates and transparent communication to safeguard modern cars against evolving cybersecurity threats.

...