As cars have become more and more digital, the potential for cybersecurity bugs has risen. Most of these can be patched by manufacturer software updates, but what if the issue isn’t in something installed from the factory? Imagine that there’s a device on your vehicle you may be unaware of, one with a security issue that allows hackers to quietly unlock it or shut it down remotely, so long as they’re within signal transmission range. Actually, you don’t need to imagine because that exact scenario is happening right now.
It’s called the KARR Security System and in theory, it’s a useful little gadget. Between dispatch fraud and vehicles being stolen off dealer lots, car theft is still a problem even before cars make their way to private hands. In theory, this little device offers GPS tracking for theft recovery, and a relatively low cost per device means that many dealerships install them on vehicles held in inventory.
Unfortunately, the KARR Security System also comes with a bunch of features that have come back to bite. Bluetooth-enabled functions like a panic alarm mode, remote locking and unlocking, and remote vehicle shutdown. As Wired reports, researchers from UC San Diego have exploited a flaw in the security system in a way that could wreak havoc should the same issue be exploited by those with bad intentions.
In a series of demos for WIRED, all captured in the video above, the researchers showed that they could use their own Android app to send Bluetooth commands to vulnerable vehicles with KARR installed to carry out a wide array of potentially disruptive or dangerous hacking. The demo exploits can, with the tap of a button, unlock a car at a stop light to enable theft or carjacking, instantly paralyze a parked car to prevent it from starting, or even—with a “mayhem” button they built into the app—hack a group of cars to simultaneously and repeatedly trigger their horns and lights, as the researchers demonstrated for WIRED in a UCSD parking lot.
While this exploit doesn’t let hackers start a vehicle with the KARR Security System, once a car’s unlocked and the OBDII port can be accessed, pairing a new key on many models is surprisingly easy. Key generators intended for locksmith use can be purchased for as little as a few hundred dollars, and once a thief has one of those and a blank smart fob, you know exactly what happens next. Even just unlocking a vehicle can grant a thief access to valuables inside, which seems like it could be a big problem for say, commercial vans that carry expensive tools.

Making matters more complicated is how this security issue is patched. If a vulnerability like this was found in software installed by an automaker, said hypothetical automaker’s database would be able to send notifications to affected owners just like recall warning letters. With KARR, not only does a patch have to be installed by owners, but dealerships often just leave the units installed on cars that go out the door even if the buyer doesn’t pay for it as an add-on. How many cars might be affected? As Wired wrote:
To get a count of how many vulnerable KARR devices are out there, UCSD researcher Yibo Wei used the open-source radio information database WiGLE, which crowdsources radio signals that contributors pick up with antennas all over the US and the world. He estimated as a result of those scans and extrapolating from the serial numbers of the devices that more than 2 million of the Bluetooth-enabled KARR devices have been deployed.
Even assuming some of the estimated two million-plus devices have effectively met their demises in mechanic’s shops, crashes, floods, and the occasional car fire, that’s still a shedload of vulnerable devices out on the roads in America and beyond.
The good news is that a security patch does exist, although it took some time to come out. As Wired wrote, UCSD researchers notified KARR developer Acrisure Protection Group of the issue back in January of 2025, “but the company didn’t offer a fix until just weeks ahead of UCSD’s planned presentations about its findings at the Defcon hacker conference and the Usenix security conference next month.” The company plans to promote the patch through the device’s app and website, as well as with “dealer communications,” but that doesn’t seem to account for some drivers who may not be aware of the device. Even if you purchased your used car privately, it could still have a KARR Security System installed.
For now, the big tell-tales of a KARR Security System installation are a sticker that says “KARR” or “SWDS” that’s usually placed on the driver’s window, or remnants of said sticker, along with a button with a light tucked under your dashboard. Should you find the device installed on your vehicle, it’s best to update it ASAP. Instructions are available on the firm’s YouTube channel for both active customers and non-active customers. Even for non-active customers, the procedure looks fairly easy. Download the app, tap “customer service,” then “firmware update,” verify your VIN, then follow the instructions on screen when it comes to cycling ignition and whatnot. Oh, and tell your friends. This is a vehicle security issue on an enormous scale, so the more people who know about it, the greater the chance of devices being manually patched.
Top graphic images: Karr Security/YouTube









Man, articles like this scare me. My mom is on a bit of a gen x /boomer yell/scream freakout about all the MY 2027 in car surveillance stuff and for once I completely agree. I’m just glad my 2022 Tacoma has a physical key and a manual transmission so it can’t be hijacked remotely.
I’ve been tasked with replacing our 2022 Toyotas with something much older once they have outlived their usefulness. Gives me a minimum of 6 years to get my act together and build some old cars to reliability.
Should be able to buy and fix up a chevy square body like I used to have and restore my mom’s ’92 S10 she bought new. Aside from the rust she refuses to drive anything without AC, luckily, I have a parts truck to rob for AC components.
That’s only if you don’t absolutely refuse to drive anything newer than approximately MY2012 like I do. Ain’t no car in my driveway getting hacked into without being in the driveway with it.
I have now lived long enough that automakers have completely turned me off to the idea of ever buying a brand new ANYTHING, ever again, precisely by making cars “better.” No thanks.
Should you find the device installed on your vehicle, it’s best to update it ASAP.
Why would I find the device and not remove it? There is zero benefit to the customer to have this installed. Zero.
The proper update procedure involves wire cutters and a garbage can.
If I bought a vehicle that had wiring messed with by the dealer, and wasn’t informed the device was in my vehicle, I’d be livid. I’m sure the new hire mechanic did a flawless job hacking up the harness that controls several critical systems.
One more reason to not buy a 2020+ vehicle.
I am guessing everyone who received this feature on their car agreed to it in the endless stream of paperwork they signed when they bought it.
KARR was KITT’s arch nemesis, right?
Well, great. Now I have to worry about thieves unlocking my cars and installing OBDII ports.
[Laughs in 33-year-old Ford Club Wagon.]
[Tilts steering wheel maximally upward, unbuckles belt, gets out of driver’s seat and walks over to side door to unlock it because the power locks module’s broken. Gets back into driver’s seat and weeps in 33-year-old Ford Club Wagon.]
Yet another article that makes me happy that we special-ordered our 2024 Trax LS so we got one with an actual key that you have to insert into the ignition and twist before you can drive it away. Don’t know about the upcoming 2027 models, but the 2026 ones are still available with this feature.
They can trigger the immobilizer remotely and all sorts of other mischief
Fortunately, nothing I own is remotely old enough for me to worry about this. 😉
Beat me to it. The newest vehicle in my fleet is a 2010. And bonus they are all paid for.
Mine are from ’89, ’95, and ’04. All purchased well-used of course, and yes, all paid for. 🙂 My house is too, which probably has something to do with my preference for older/cheaper cars instead of getting new car loans all the time.
I still think that four pedals and a now five speed semi non syncro right lever gearbox in a RHD car is good enough as a theft deterrent. The rebuilt gearbox is a joy, crash and clutch from neutral to first, double into second, and then so smooth, third, check revs and pressure, without a thought, fourth just comes so nicely, filth is full on overdrive. An easy lope at 90mph,1000rpm.Eight litres of goodness!
With “eight liters of goodness” and gas prices what they are I’d think a better lock on your petrol filler and an armoured plate protecting the presumably voluminous petrol tank would be the theft deterrents that matter
I am not allowed to tell, on a good day, driven gently it does about 11mpg, the fuel filler has a lock, both actually. The fuel depot is the big trunk thing at the back. It is surprisingly theft proof, the plating was for the Peking to Paris jolly. Before you ask, when full it can have 600 gallons of fuel!
Soooo where exactly do you park it and when might it be there for say a few hours?
It is back to normal now, the tanks that were attached are somewhere in the Gobi desert. three 40 gallon drums each side, a relativity simple plan, over a a massive and mainly empty bit of the world do you either set up fuel dumps and helicopter support or bash old oil drums to fit on the running boards until they fit? Above the roof there was a tank from a De Havilland aeroplane, this worked!
It is now my daily car( i have a near dead Mk1 Leaf too) The tank on the Bentley only holds 26 gallons now and it is parked in it’s shed. There are geese, and a mad hippy with a shotgun.
In a shed? with geese? and a mad hobo with a shotgun?
It’s safer there than in Fort Knox!
(yes I know you said “hippy” but I couldn’t resist:
https://en.wikipedia.org/wiki/Hobo_with_a_Shotgun)
Now I have watch that!
I’d be interested in knowing if any Autopian readers actually find one of these devices in their car.
Seems unlikely. A site-wide survey would probably come in around 38%.
That Flipper thing that the internet’s been going on about for the past few years does this sort of thing: allowing a user to capture, save, and send signals in a multitude of ways, including all sorts of remotes.
If I were 14 again, I’d be into experimenting with all this hackery, but I’m tired now, so I don’t.
Out of curiosity, I used my Flipper to see if I could “record” the door lock/unlock signals from the key of my at-the-time company issue 2015 Focus. It did not have remote start and was still a physical key.
The result was….it worked! Once. The flipper did successfully send an unlock signal and the driver door unlocked. However, then after that, neither the flipper OR the actual key remote worked anymore.
I was able to get the actual key remote working again by a process I found on youtube to relearn the remote. There was some convoluted process of cycling the ignition, holding the lock/unlock buttons, ect. It required the fob and physical key be present, as the physical key also has the PATS chip in it (Ford’s with a key have had that since the jellybean F150 era).
What I found re: why it worked, but only once, is that it uses a rolling code system, a “call and response”. So each code is only good for one successful action. However if the remote doesn’t get a “received” feedback signal from the car, it does not advance to the next code. So if you click the remote nowhere near the car, it doesn’t get borked/out of sync and then not work since the remote and car are now on different codes. Your garage door remote works more or less the same way, unless it’s something more than 30 years old or so.
I guess the reason the flipper worked once, even being it recorded a code that was “used” that instant, the car may offer a certain “grace” or slight error correction in case for some reason the key doesn’t get the “received” signal and re-transmits the code again. But that grace is apparently only once, then it locks out and requires a key relearn.
That was interesting and potentially useful info MP… thanks! 🙂
My garage door remote is probably safe, just like my cars. 😉
The last 4 vehicles in the household have had some kind of a KARR security system. Dealers use them. While they are security systems, I think the reap reason dealers use them is because it lets salespeople unlock cars from their phones.
Then instead of removing them when they sell the car, they try to charge you for them as a dealer accessory. If don’t buy it, they just leave it (supposedly) deactivated in your car.
I have one on one of our cars, or at least something similar. Labelled as some Chrysler service. I understood them to help with repo – find the car and disable it for retrieval?
Coming next week: Using a cheap Chinese gizmo to open Tesla charge port doors and annoy the owners. (-;
F’n smart F’n ain’t.
Oh no hackers may be able to break into my 21 year old car and take my collection of Daft Punk CD’s.
To be fair, Daft Punk rocks.
Correction: Daft Punk Robot Rocks.
It’s hard to break in to the old cars since coat hangers became plastic.
It’s hard to do lots of things since coat hangers became plastic. Improvising an exhaust hanger, for example.
I still have some wire coat hangers and pieces of wire hanger carefully hidden in the garage for those times that bailing wire just isn’t stiff enough.
Still all wire or wood here. I have the history of dry cleaners, hotels, and tailors in LA, San Francisco, NYC, and a few other places.
Coat hanger wire is pretty useless for breaking into cars. Steel flashing, a couple of skinny 12 inch screwtdrivers, and a vice grip do the trick. Some case hardened sheet metal screws if you are going medieval. Steel banding strap off a shipping crate is great stuff. A stainless steel drafting ruler if you need plausible deniability for random stuff in your trunk according to a friend that does that sort of thing.
They may replace them with Ted Nugent 8-tracks, just to teach you a lesson.
Our 13 year old car has a similar problem They could get Daft Punk, unlike my truck where they will find pirated Hardbass
If that’s your worry just clone your Daft Punk CD collection for the car and keep the originals at home.
I did copy one album to cassettes but the quality was not the same.
Its quite easy to make 1:1 copies of CDs onto CDRs using a computer. Since it’s 1:1 there is no loss of quality. And yes, it is legal to make backup copies.
On top of that if you find your CD has become damaged and no longer plays correctly you can rip the damaged tracks from borrowed CDs to make a better copy*. Or make compilation CDs. With the right software which you should be able to find free online you can also add album info like the cover art and lyrics to the tracks to display in more modern players.
* AFAIK that does not violate copyright as long as you own a copy of the original track. If that copy happens to be a decades old sun baked 8-track or dog chewed casette tape, well let the lawyers muse on that.
I’m sure I read a story about a man who found one of these units under the dash of his new car. He took it out and a day later his dealer called asking why he disconnected it. When he said he didn’t like being spied on they asked him to bring it back. He refused but told them they could come get it. I don’t think they did.
Just watched a video from a lawyer that likely involved this system or one similar. Look up Shane Sprague. Guy buys new truck. Signs paperwork, pays, and drives away. 10 days later the dealership manager reports truck stolen. Cops follow the tracker and ram the truck, arresting him at gunpoint.
Turns out the dealership wrote all the paperwork for a different truck, never actually changed over the title for the one that was sold, and never asked the sales staff if someone sold that truck.
So you’re saying I need a KITT to fix my KARR?
“Instead of being a problem ridden prototype, I’m the new improved model.”
Those hackers finally fixed my key fob, eh?
“Should you find the device installed on your vehicle, it’s best to update it ASAP.”
I’d rather just rip it out by the short wires and be done with it.
Can we get a tutorial for that please?
I was curious and found this about removing KARR: https://www.civic11forum.com/threads/diy-removal-of-karr-security-system.5646
BTW – If you want to disable the telematics from your Tundra or Lexus, this might be of use: https://www.autoharnesshouse.com/
Yup that is the correct response.
As far as removal goes it is pretty straight forward. Of course it is going to vary somewhat based on make, model and who installed it. But the key thing is to reconnect the wire that was cut. Depending on the vehicle and who installed it that cut wire maybe for the starer, fuel pump or maybe even the shift interlock.
I documented it as shown in the link below. I got a used ES300h, and saw a non-stock button or LED light under the dash and knew something was up. No KARR sticker anywhere. Whoever installed it did not take much care, as some of the panels had bent tabs.
https://www.clublexus.com/forums/es-7th-gen-2019-2025/1024986-how-do-i-remove-these-kick-panels-to-remove-karr-alarm.html