KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars
ID: b527ed13-b4cd-5970-ba16-771692606b80
STIX ID: report--b527ed13-b4cd-5970-ba16-771692606b80
Feed Name: GBHackers
Researchers at UC San Diego disclosed a critical Bluetooth authentication vulnerability in dealer-installed KARR aftermarket alarm systems that lets nearby attackers issue commands (lock/unlock, disable alarms, trigger horn/lights, and prevent engine start) by exploiting a shared embedded key discovered through reverse engineering; a proof-of-concept Android app and field testing indicated widespread exposure (estimated 2.2 million units and dozens of vulnerable vehicles locally). Acrisure released a firmware patch on July 20, 2026 and vehicle owners are advised to install the KARR Security app and apply the update, highlighting broader risks posed by undocumented aftermarket hardware and persistent Bluetooth broadcasts that can enable theft or tracking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
