728 x 90

2 Million Cars at Risk of Sneaky Bluetooth Hack Opening Doors

2 Million Cars at Risk of Sneaky Bluetooth Hack Opening Doors

Receive the daily Popular Science newsletter💡 Breakthroughs, discoveries and DIY tips delivered six days a week. By registering, you confirm that you are over 16 years of age, will receive newsletters and promotional content, agree to our Terms of Use, and acknowledge the data practices in our Privacy Policy. You can unsubscribe at any time.

A security vulnerability affecting at least two million vehicles on the road today is so serious that some cybersecurity experts are calling it one of the worst car hacking threats in years. This is a third-party device called KARR Security System. When exploited, the threat potentially offers attackers a way to wirelessly unlock a vehicle’s doors or prevent it from starting.

While Acrisure Protection Group has released a software update to fix the problem, many drivers who have the device connected to their car never paid for it and may not even know it is installed. The device was installed in several models of major car brands, including Honda, Toyota, Mazda, Ford and Jeep, although many of those cars have since spread to other states and even as far as Canada and Japan.

The compromised device was initially sold as an anti-theft tool for car dealerships. In a twist of irony, the device actually makes it theoretically easier for a thief to surreptitiously drive away with someone else’s car. Researchers at the University of California, San Diego (UCSD) demonstrated that with a custom app, they could ping the device wirelessly via Bluetooth. With a few clicks, they could lock or unlock the doors, honk the horn, turn on the lights, or even prevent the car from starting if the engine was already off.

Acrisure Protection Group reportedly learned of the vulnerability from researchers in January 2025, but did not issue a software patch until July 20, 2026.. When popular science When we contacted Acrisure for comment, we received a statement from KARR Security, a product line of the company responsible for manufacturing the device with the vulnerability.

Karr Security said popular science You haven’t seen the vulnerability that applies in the real world to breaking into or stealing a car.

“UC San Diego researchers have identified a vulnerability affecting BLE-based car theft devices, including a small percentage of KARR devices with certain Bluetooth-related components,” KARR Security said. “The vulnerability described in the research is very complex and presents a low risk to customers under real-world conditions.”

“However, we responded quickly and developed a firmware update to fix the issue,” they continued.

2 million cars with dealer-installed anti-theft systems are at increased risk of theft.

2 million cars with dealer-installed anti-theft systems are at increased risk of theft

Notably, the hack doesn’t start the car’s engine, meaning a thief can’t drive using anything but your phone. However, UCSD researchers showed that once inside, a car thief could use “locksmith key cloning tools” available on the Internet to extract the key from a car’s computer and use it to turn on the ignition. The worst case scenario is that someone sneaks into the car using the Bluetooth trick and sneaks away silently, without having to break a window or move a lock. These actions could potentially trigger an alarm or attract attention.

“Instead of breaking a window to gain access to a vehicle, thieves could simply connect remotely via a Bluetooth device inside the vehicle and unlock the vehicle’s doors,” UCSD Masters winner Jerry Yu said in a blog post. Yu and the rest of the team behind the research plan to present their research at this year’s Defcon cybersecurity conference in early August.

Stefan Savage, a UCSD computer science professor who was not involved in this research, said cabling this week that the KARR security flaw is “probably the worst” car hacking threat he has ever seen.

The KARR device looks like a small flashing button located at the bottom of the driver’s side dashboard. It connects to the car’s computer system that controls key safety functions. That device then connects to a smartphone app via Bluetooth. The idea is that a dealership installs these devices primarily as a means to help keep track of inventory and prevent theft from the lot. Once the car is sold, the dealer tries to sell access to the device to the new driver as a paid add-on. A percentage of drivers will say yes and then access the tool using the KARR consumer smartphone app. Those drivers should receive an alert in the app telling them to update the software with the fix immediately.

But many drivers chose not to pay for the service. Even if they don’t actively use the device, it is often still physically there, connected to the computer and the car’s ignition system, and is still susceptible to vulnerability. Drivers who purchased these cars on the secondary market at some point in the last nine years also have no idea they are driving a compromised car. Many of the cars with the device installed will have a “KARR” sticker on the driver’s side window or a sticker that says SWDS (short for Southwest Dealer Services). Concerned drivers can also look for a small flashing button located at the bottom of the car’s dashboard. That said, it is not advisable to simply boot the device. Since it is connected to an important system, removing it incorrectly risks creating even worse problems.

“Many car owners don’t even know their vehicle is vulnerable,” UCSD Department of Computer Science and Engineering professor and lead author of the study Aaron Schulman said in a blog post. “That’s why we wanted to make sure they were aware by publishing this study.”

One key to hack them all

The hack is made possible by a vulnerability in a single authentication key shared among all KARR devices. Each device used the same key, which the researchers essentially compared to a password that read “1234.” Once a researcher (or hacker) gained access to a device, they basically had the keys to all of them. In other words, breaking into one device meant breaking into all of them. The researchers were able to reverse engineer the KARR smartphone app code and use their own malicious app to connect to the device via Bluetooth, accessing it as if they were the legitimate owner of the car. Using this method, UCSD researchers opened car doors, honked the horn, and turned on the lights.

In its statement, KARR Security emphasized that the proposed hack requires a lot of technical understanding to achieve and said the patch should fix the issue. Ensuring that the more than two million affected drivers receive the update (or even know to look for it) is much more complicated. There are some steps worried drivers can take. If they see the sticker or can find the device, they should download the app and check for the update.

Acrisure also said it hopes to alert other drivers who may not know they have the compromised device through “dealer communications,” although it’s not entirely clear what that means.

“Active customers can apply the update directly from their phone after securely signing in to the KARR Security app,” KARR Security said Popular science. “Owners of vehicles with non-active systems can still update through the app using their VIN (last 8 digits) as a validation step.”

“This update must be installed even if you are a vehicle owner and did not activate the system when you purchased your car from the dealership,” Schulman said in a YouTube video breaking down the research.

Cars are now essentially computers, for better or worse

Security researchers have been warning about a vulnerability like this occurring for the better part of a decade. As modern cars continue to integrate more of their core systems with computers, they are increasingly vulnerable to the same types of attacks that software companies protect laptops and mobile devices against. Increasingly connected cars are becoming what some call “smartphones on wheels.” That’s a plus for automakers, who can then charge drivers to activate certain features like heated seats, autonomous parking and even extra horsepower for electric vehicles for a subscription price. And all this is possible thanks to over-the-air software updates. However, that constant digital coming and going also opens up more avenues for hackers to find a way in.

However, this change is not entirely negative. Over-the-air updates mean that automakers can release fixes for minor problems much faster than. Today, cars can undergo a massive recall and then be fixed in a matter of hours or days, without the driver having to go to a shop. That consistent, proactive solution can prevent bigger problems down the road. Drivers also have more choice, or at least the appearance of choice, in the types of accessories and additional features they decide to pay for.

Still, all of that comes with an inevitable trade-off. For better or worse, modern cars are just another Internet-connected device, which means people need to get into the habit of updating their cars periodically, just as they would with the rest of the technology on their desks.

products on a page that says the best of what's new in 2025

2025 PopSci Best of what’s new

Mack DeGeurin is a technology reporter who has spent years investigating where technology and politics collide. His work has previously appeared in Gizmodo, Insider, New York Magazine, and Vice.


Keep following us for the latest insights.

Posts Carousel

Latest Posts

Top Authors

Most Commented

Featured Videos