Popular Posts

Hidden Hazard: Aftermarket Car Alarms Expose Millions of Vehicles to Remote Hacking and Paralysis

As modern automobiles increasingly resemble sophisticated, multi-ton computers on wheels, drivers are becoming accustomed to the necessity of installing security updates for their vehicle’s software, much like they would for a smartphone or laptop. However, even the most technologically adept car owners would not anticipate the need to patch a vulnerability in an insecure, third-party component that they neither installed nor requested, and of which they are likely entirely unaware. This component, wired into some of the most critical systems of their vehicle, has been found to leave it exposed to stealthy hacking, insidious tracking, and even roadside immobilization.

This alarming discovery was made by a dedicated team of security researchers at UC San Diego. They uncovered a severe flaw in a specific model of aftermarket car alarm, the KARR Security System, which they estimate has been installed in over 2 million vehicles across the United States. The vulnerability allows any hacker within Bluetooth range to send radio commands to these devices, enabling them to silently unlock the car at will, deactivate its alarm, trigger its horn or flash its lights, or even disable its ignition, potentially leaving a driver stranded and vulnerable.

The KARR alarm devices are typically installed by car dealerships, not by vehicle manufacturers or the owners themselves. Their primary purpose is often to deter auto theft from dealer lots. Crucially, when these vehicles are sold, the KARR alarms are frequently not removed, even if the buyer explicitly declines to purchase it as an additional feature. This pervasive practice means that countless car owners nationwide unwittingly possess a hackable device integrated into their vehicle’s sensitive systems—a device whose code requires an update for protection, yet one they never acquired and whose very presence they are often oblivious to.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

"This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars," stated Aaron Schulman, the UC San Diego computer science professor who spearheaded the research. "It’s designed to make cars more secure, but ultimately it’s created a vulnerability that needs to be patched immediately across millions of vehicles. We’re trying to get the word out that you need to check your car for this device and manually patch it now."

In response to the UCSD findings, Acrisure Protection Group, the company that markets the KARR Security System, has recently released a firmware update designed to rectify the security flaws identified in its Bluetooth-enabled KARR alarm model. Car owners who have already installed the KARR Security smartphone application should receive an alert prompting them to apply the firmware update. For those who do not have the app, it is necessary to download the KARR Security System smartphone app (available on Android and iOS), connect it to their vehicle’s KARR alarm, and then navigate to "customer service" followed by "firmware update" within the application.

Identifying whether your vehicle is equipped with this potentially vulnerable device can be straightforward. According to UCSD’s estimates, at least half of the car owners with a KARR device installed did not request it. Owners should look for a KARR sticker affixed to their car’s driver-side window. In some instances, a sticker bearing "SWDS" for SouthWest Dealer Services, a subsidiary of Acrisure Protection Group, may be present. Additionally, a small button with a blinking light often attached to the underside of the car’s dashboard can indicate the device’s presence. While the KARR system is particularly popular among car dealers in Southern California, leading to a higher concentration of affected vehicles there, UCSD researchers caution that they have detected these devices in cars across the entire United States and even in other countries, highlighting a widespread security concern.

Stefan Savage, another distinguished UC San Diego computer science professor, who notably co-led the pioneering team that hacked a car’s steering and brakes in 2010 and 2011, described the KARR’s security flaw as "probably the worst" car hacking threat ever uncovered. He explained the gravity of the situation: "It affects a large number of vehicles, the manufacturer of your car can’t fix it, and you don’t even know you have the problem. It provides all the elements a car thief would want, but you have none of the advantages we normally have in terms of defending it, because you’re disconnected from the supply chain that put it there." This unique confluence of broad deployment, stealth installation, and difficult remediation elevates the KARR vulnerability beyond typical automotive security concerns.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

When WIRED contacted Acrisure Protection Group regarding the KARR security flaw, a spokesperson issued a statement asserting, "The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions. Nevertheless, we responded promptly and developed a firmware update to address the issue." The company further stated its intention to notify car owners about the patch via the KARR Security app, the KARR Security website, and through "dealer communications." However, the statement provided no further details on how it plans to effectively reach the vast number of car owners who are unaware of the device’s installation in their vehicles, including those who may have purchased affected cars secondhand and are no longer traceable by original dealerships.

Despite Acrisure Protection Group’s assertion of having patched the flaw "promptly," the timeline of events suggests a significant delay. The UCSD researchers initially informed the company of the vulnerability in January of the previous year, meaning it took nearly 18 months for a fix to be released. The firmware update only became available weeks before UCSD’s scheduled presentations detailing their findings at the prestigious Defcon hacker conference and the Usenix security conference next month, raising questions about the true urgency of their response.

Furthermore, Acrisure’s claim that the vulnerability poses a "low risk" under "real-world conditions" warrants considerable skepticism when juxtaposed with the UCSD team’s demonstrations. In a series of compelling proofs-of-concept presented to WIRED, captured in video, the researchers effectively used their custom-built Android application to transmit Bluetooth commands to vulnerable vehicles equipped with the KARR system. These demonstrations illustrated a wide array of potentially disruptive or dangerous hacking capabilities. With a mere tap of a button, the exploit could unlock a car at a traffic light, facilitating theft or carjacking. It could instantly immobilize a parked car, preventing it from starting, a tactic that could leave a driver stranded in a perilous situation. The researchers even showcased a "mayhem" button they integrated into their app, which could simultaneously and repeatedly trigger the horns and lights of multiple hacked cars, as dramatically demonstrated in a UCSD parking lot.

While the KARR Security System’s vulnerabilities do not, thankfully, enable a hacker to directly start a car’s ignition, the UCSD researchers illustrated how this flaw could be combined with other common criminal techniques. Once a car thief gains stealthy entry into a vehicle using the KARR vulnerability, a readily available locksmith tool, often resold online, can be plugged into the car’s dashboard. This tool can then generate a functional key within a matter of minutes, allowing the thief to drive the car away. Traditionally, car thieves using such tools would first need to force entry, often by breaking a window or employing car-door opening implements, actions that typically trigger a car alarm. The KARR vulnerability, however, bypasses these deterrents, granting silent and undetected access, making the subsequent theft much easier to execute.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

The fundamental security flaw enabling these sabotage and intrusion tricks, as pinpointed by the UCSD team, is the presence of a single, universal authentication key shared across all KARR devices. The UCSD researchers discovered this key embedded within the code of the KARR smartphone application, which legitimate customers utilize to control their alarms. By leveraging this universal key and their own custom application, meticulously crafted through reverse engineering the KARR app’s code, they found they could spoof radio commands that would be accepted by any nearby Bluetooth-enabled KARR device. This shared key represents a critical design oversight, creating a single point of failure that compromises the security of every KARR system deployed.

Compounding the KARR device’s inherent insecurity is its operational behavior. Even when a car buyer declines to pay for the system as an add-on, the device remains installed in the vehicle. It continuously beacons out and accepts Bluetooth signals whenever the car is running, and for an extended period of up to 10 minutes after the car has been turned off. While for these non-paying drivers the KARR device is supposedly in a "deactivated" state, the researchers discovered that they could readily activate it with a simple radio command and immediately proceed to execute their full menu of hacking techniques. This activation does produce a brief beep from the car’s horn and a flicker of its lights, which would be the only subtle indication to an unaware car owner that their vehicle has been put into a hackable state. For the hundreds of thousands of KARR customers who explicitly paid a dealer to enable the alarm system, no such warning would be received, leaving them entirely vulnerable without any sign of compromise.

The genesis of this significant discovery dates back to 2018 when UCSD researcher Nishant Bhaskar first became aware of the KARR devices. While conducting an analysis of radio-enabled "skimmer" devices, which are designed to illicitly capture credit card information from gas station point-of-sale terminals, he began detecting mysterious Bluetooth signals emanating from these gas stations. Soon after, he realized he was encountering the identical radio signals on highways, originating from a diverse range of vehicle makes and models. It was at this point that he initiated an online search for the text-based prefixes of these persistent Bluetooth signals, eventually identifying them in a Federal Communications Commission database as belonging to the KARR alarm device.

Years later, in 2024, when then-graduate researcher Jerry Yu was seeking a summer project, Professor Schulman suggested he investigate the security of the KARR device whose signals Bhaskar had initially observed. Yu quickly identified the KARR app’s universal authentication key, a glaring and fundamental security flaw. "Once we reverse-engineered their application, we quickly realized after understanding their internal authentication protocol that it was so simple that we could extract it and re-implement it as our own application, which we did," Yu explained. This custom application, they discovered, possessed the capability to unlock "every single car they’ve ever put this in."

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

To ascertain the sheer number of vulnerable KARR devices in circulation, UCSD researcher Yibo Wei leveraged the open-source radio information database WiGLE. This extensive database crowdsources radio signals collected by contributors using antennas across the United States and globally. Through meticulous analysis of these scans and by extrapolating from the serial numbers of the devices, Wei estimated that more than 2 million Bluetooth-enabled KARR devices have been deployed, indicating a truly widespread risk.

These WiGLE results serve a purpose beyond mere measurement. They also present a potential avenue for malicious actors. The database could allow a hacker to track the historical locations of vulnerable cars based on their KARR device’s unique Bluetooth signature. This data could then be used to identify places where a vehicle is frequently parked, offering a disturbingly straightforward scouting mechanism for criminals to pinpoint opportune moments and locations to hack vehicles for theft or sabotage.

In the UCSD team’s own localized scanning efforts, they consistently encountered KARR-enabled vehicles almost everywhere they looked. During a brief 20-minute drive around the outskirts of the university’s campus, while actively scanning for cars emitting beaconing KARR device signals using their app on a standard Android phone, the researchers detected an astonishing 97 vehicles equipped with the vulnerable alarms.

Professor Schulman and his dedicated team now feel a profound responsibility to alert every one of these drivers about the hidden, hackable gadget lurking within the critical systems of their vehicles. "When you install something by default at a dealer in every car that’s sold, the pervasiveness of that vulnerability is going to be unimaginable," he emphasized. "This is why we need to publicize this and get it out there, because the only way this will eventually get solved is if we get everyone on board and to fix it themselves." The incident underscores the growing complexities of automotive cybersecurity and highlights the urgent need for greater transparency and consumer awareness regarding third-party components integrated into modern vehicles.

Leave a Reply

Your email address will not be published. Required fields are marked *