logo

KARR Bluetooth Vulnerability Lets Nearby Attackers Unlock and Immobilize Over 2 Million Cars

ID: b527ed13-b4cd-5970-ba16-771692606b80

STIX ID: report--b527ed13-b4cd-5970-ba16-771692606b80

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Divya

...
...

Researchers at UC San Diego disclosed a critical Bluetooth authentication vulnerability in dealer-installed KARR aftermarket alarm systems that lets nearby attackers issue commands (lock/unlock, disable alarms, trigger horn/lights, and prevent engine start) by exploiting a shared embedded key discovered through reverse engineering; a proof-of-concept Android app and field testing indicated widespread exposure (estimated 2.2 million units and dozens of vulnerable vehicles locally). Acrisure released a firmware patch on July 20, 2026 and vehicle owners are advised to install the KARR Security app and apply the update, highlighting broader risks posed by undocumented aftermarket hardware and persistent Bluetooth broadcasts that can enable theft or tracking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.