Home » Hackers May Be Able To Remotely Unlock Or Disable Your Car Via A Security System You Don’t Even Know You Have, But The Fix Is Easy

Hackers May Be Able To Remotely Unlock Or Disable Your Car Via A Security System You Don’t Even Know You Have, But The Fix Is Easy

Karr Security Ts

As cars have become more and more digital, the potential for cybersecurity bugs has risen. Most of these can be patched by manufacturer software updates, but what if the issue isn’t in something installed from the factory? Imagine that there’s a device on your vehicle you may be unaware of, one with a security issue that allows hackers to quietly unlock it or shut it down remotely, so long as they’re within signal transmission range. Actually, you don’t need to imagine because that exact scenario is happening right now.

It’s called the KARR Security System and in theory, it’s a useful little gadget. Between dispatch fraud and vehicles being stolen off dealer lots, car theft is still a problem even before cars make their way to private hands. In theory, this little device offers GPS tracking for theft recovery, and a relatively low cost per device means that many dealerships install them on vehicles held in inventory.

Vidframe Min Top
Vidframe Min Bottom

Unfortunately, the KARR Security System also comes with a bunch of features that have come back to bite. Bluetooth-enabled functions like a panic alarm mode, remote locking and unlocking, and remote vehicle shutdown. As Wired reports, researchers from UC San Diego have exploited a flaw in the security system in a way that could wreak havoc should the same issue be exploited by those with bad intentions.

In a series of demos for WIRED, all captured in the video above, the researchers showed that they could use their own Android app to send Bluetooth commands to vulnerable vehicles with KARR installed to carry out a wide array of potentially disruptive or dangerous hacking. The demo exploits can, with the tap of a button, unlock a car at a stop light to enable theft or carjacking, instantly paralyze a parked car to prevent it from starting, or even—with a “mayhem” button they built into the app—hack a group of cars to simultaneously and repeatedly trigger their horns and lights, as the researchers demonstrated for WIRED in a UCSD parking lot.

While this exploit doesn’t let hackers start a vehicle with the KARR Security System, once a car’s unlocked and the OBDII port can be accessed, pairing a new key on many models is surprisingly easy. Key generators intended for locksmith use can be purchased for as little as a few hundred dollars, and once a thief has one of those and a blank smart fob, you know exactly what happens next. Even just unlocking a vehicle can grant a thief access to valuables inside, which seems like it could be a big problem for say, commercial vans that carry expensive tools.

Karr Security 1
Photo credit: Karr Security

Making matters more complicated is how this security issue is patched. If a vulnerability like this was found in software installed by an automaker, said hypothetical automaker’s database would be able to send notifications to affected owners just like recall warning letters. With KARR, not only does a patch have to be installed by owners, but dealerships often just leave the units installed on cars that go out the door even if the buyer doesn’t pay for it as an add-on. How many cars might be affected? As Wired wrote:

To get a count of how many vulnerable KARR devices are out there, UCSD researcher Yibo Wei used the open-source radio information database WiGLE, which crowdsources radio signals that contributors pick up with antennas all over the US and the world. He estimated as a result of those scans and extrapolating from the serial numbers of the devices that more than 2 million of the Bluetooth-enabled KARR devices have been deployed.

Even assuming some of the estimated two million-plus devices have effectively met their demises in mechanic’s shops, crashes, floods, and the occasional car fire, that’s still a shedload of vulnerable devices out on the roads in America and beyond.

The good news is that a security patch does exist, although it took some time to come out. As Wired wrote, UCSD researchers notified KARR developer Acrisure Protection Group of the issue back in January of 2025, “but the company didn’t offer a fix until just weeks ahead of UCSD’s planned presentations about its findings at the Defcon hacker conference and the Usenix security conference next month.” The company plans to promote the patch through the device’s app and website, as well as with “dealer communications,” but that doesn’t seem to account for some drivers who may not be aware of the device. Even if you purchased your used car privately, it could still have a KARR Security System installed.

For now, the big tell-tales of a KARR Security System installation are a sticker that says “KARR” or “SWDS” that’s usually placed on the driver’s window, or remnants of said sticker, along with a button with a light tucked under your dashboard. Should you find the device installed on your vehicle, it’s best to update it ASAP. Instructions are available on the firm’s YouTube channel for both active customers and non-active customers. Even for non-active customers, the procedure looks fairly easy. Download the app, tap “customer service,” then “firmware update,” verify your VIN, then follow the instructions on screen when it comes to cycling ignition and whatnot. Oh, and tell your friends. This is a vehicle security issue on an enormous scale, so the more people who know about it, the greater the chance of devices being manually patched.

Top graphic images: Karr Security/YouTube

 

 

 

 

 

Share on facebook
Facebook
Share on whatsapp
WhatsApp
Share on twitter
Twitter
Share on linkedin
LinkedIn
Share on reddit
Reddit
Subscribe
Notify of
2 Comments
Inline Feedbacks
View all comments
Mechjaz
Member
Mechjaz
19 minutes ago

Those hackers finally fixed my key fob, eh?

Urban Runabout
Member
Urban Runabout
29 minutes ago

Should you find the device installed on your vehicle, it’s best to update it ASAP.”

I’d rather just rip it out by the short wires and be done with it.
Can we get a tutorial for that please?

2
0
Would love your thoughts, please comment.x
()
x