KARR Car Alarm Flaw Lets Nearby Attackers Unlock and Immobilize Vehicles
ID: fca89ff2-6822-55c3-aebf-3ca2a11b3401
STIX ID: report--fca89ff2-6822-55c3-aebf-3ca2a11b3401
Feed Name: Cyber Press
A UC San Diego research team discovered that the dealer-installed KARR Security aftermarket car alarm uses a universal, hardcoded Bluetooth authentication key embedded in the official app, enabling a PoC Android app to impersonate the app and remotely unlock vehicles, disable alarms, sound horns, flash lights, and prevent engines from starting; researchers estimate over 2.2 million Bluetooth-enabled KARR units are deployed across the U.S., vendor released a firmware patch in July 2026, and no evidence of active exploitation was found.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
