Tech News

Bluetooth Security Flaw Leaves 2.2 Million Cars Vulnerable, but Europe Is Mostly Unaffected

The automotive world is on edge: due to a security flaw, at least 2.2 million vehicles can be unlocked remotely over Bluetooth by anyone standing within five meters. The issue lies in a unit found in many vehicles that uses a unique cryptographic key. Here’s what we know about this potential threat.

A Single Cryptographic Key: A Design Mistake

Let’s start by naming the culprit right away: this security flaw affects all KARR Security System and SWDS anti-theft systems, sold by Acrisure Protection Group. These BLE (Bluetooth Low Energy) units are installed under the dashboard on the driver’s side and are controlled through a mobile app: door lock and unlock, flashing the headlights, sounding the horn, and preventing the engine from starting until it is running.

The problem is that a team of researchers identified a major security issue: all KARR-SWDS devices rely on the same authentication key, and it is stored in plain text in the official app. Once the key was extracted, the researchers were able to communicate with any equipped vehicle. Since the key is the same across all units, that is effectively the same as having the key to every vehicle equipped with one. Ouch.

Researchers at the University of California in San Diego (UC San Diego) estimate that this is equivalent to "setting all passwords on a product line to 1234 and making it impossible to change the password".

In practice, this enables a set of actions that make vehicle theft easier:

  • Silent door unlocking from about 5 meters away, with no alert for the owner
  • Immobilizing a parked vehicle, which could leave a driver stranded
  • Triggering the horn and lights, including on multiple cars at once (imagine the scene)
  • Tracking: the units continuously broadcast Bluetooth identifiers, which participatory radio databases such as WiGLE have logged for years, according to Malwarebytes

However, it is important to note that this flaw does not allow the engine to be started remotely. But still, for someone with bad intentions, it removes the need to break in. "Instead of breaking a window to access a vehicle, thieves could simply connect remotely over Bluetooth to the unit in the car and have it unlock the doors," explains Jerry Yu, a PhD student at UC San Diego.

A Unit You May Never Have Bought

Some people may be thinking: "I never bought this kind of unit, so I’m not affected." - It’s not that simple. The real question is rather: "Is this unit present in my vehicle?"

It should be noted that the unit is installed directly by the dealership to manage its vehicle fleet. The anti-theft option is then offered to the buyer as a paid service. If the buyer declines, the hardware remains in place and stays reachable: according to the researchers, a dormant device accepts a Bluetooth wake command before exposing the same functions.

As a result, about half of the affected owners never requested this equipment. Most of the vehicles were purchased since 2017 from Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California. After that, the vehicles could go on to live elsewhere across the United States, as well as in Canada and even Japan, according to the study. What you need to check is whether you have a "KARR" or "SWDS" (for SouthWest Dealer Services) sticker on your car’s driver-side window.

In total, at least 2.2 million vehicles are affected. A sign of just how popular these units are across the Atlantic. There is little chance these units are present in vehicles in France or even in Europe (they are distributed only through the North American network). But since I know some of you are in Canada, the information matters.

Eighteen Months Between Disclosure and the Fix

Acrisure was alerted by the researchers in January 2025: no, that is not a typo, we are indeed talking about 2025. The patch, meanwhile, arrived through a firmware update released on July 20, 2026, a few weeks before the work was presented at DEF CON (August 9, Las Vegas). That feels a bit like a deadline, which is unfortunate. The researchers also did the right thing by notifying the National Highway Traffic Safety Administration, the U.S. federal agency responsible for road safety.

The problem is how this patch is distributed: it rolls out through the KARR app, which only paying customers have installed. For everyone else, the app must be downloaded, paired with the alarm, and then the update must be launched from the service menu. It is highly likely that some vehicles will never be patched against this vulnerability if dealerships do not help.... If you want to dig deeper into the topic: the researchers’ report is available on this page, along with a report published by Malwarebytes.

author avatar
Florian Burnel Co-founder of IT-Connect
Systems and network engineer, co-founder of IT-Connect and Microsoft MVP "Cloud and Datacenter Management". I'd like to share my experience and discoveries through my articles. I'm a generalist with a particular interest in Microsoft solutions and scripting. Enjoy your reading.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.