More than 2.2 million vehicles across the United States, Canada, and Japan are carrying a silent vulnerability that could allow thieves to unlock doors and disable engine starts using nothing more than a Bluetooth connection from a few yards away. The flaw lies not in the vehicles themselves, but in aftermarket anti-theft systems manufactured by Acrisure and sold under the KARR Security Systems and SWDS brands — modules that are often installed by dealerships without the buyer’s full awareness. Researchers at UC San Diego’s Department of Computer Science and Engineering uncovered the vulnerability and will present their findings at DEF CON on August 9 and the USENIX Security Symposium on August 12, having responsibly disclosed the issue to the affected vendors and the US National Highway Traffic Safety Administration beforehand.
The core problem is astonishingly simple for such a widespread security failure: every single KARR and SWDS device shares the same cryptographic key for Bluetooth authentication. By reverse engineering the system, the researchers recovered that shared key, granting them the ability to authenticate with any vulnerable module within roughly five yards of the target vehicle. Once authenticated, an attacker can remotely unlock the doors, flash the headlights, sound the horn, and — most critically — prevent the engine from starting. While the flaw does not directly enable a thief to start the engine, the ability to unlock the vehicle and block its ignition dramatically lowers the barrier to theft, effectively turning a secure car into an accessible target for anyone with a smartphone and the right tools.
The Shared Key Problem at the Heart of 2.2 Million Vehicles
The vulnerability affects Bluetooth-enabled modules manufactured by Acrisure, an insurance and financial services company that also provides aftermarket automotive security products through dealership networks. These modules are commonly installed by dealers to manage vehicle inventory before sale — allowing them to track, lock, and unlock cars on the lot remotely. After the vehicle is sold, the same hardware is marketed to buyers as an optional anti-theft system and smartphone control package. The catch is that the hardware remains physically installed and active even when customers decline the optional service, leaving millions of owners unaware that the vulnerable equipment is present in their vehicles.
Researchers estimate that at least 2.2 million vehicles sold since 2017 are affected. The primary dealerships involved include those for Honda, Toyota, Mazda, Ford, and Jeep in Southern California, but because these vehicles have since been resold multiple times across the secondary market, the vulnerable cars are now widely distributed throughout the United States, Canada, and Japan. Owners can identify potentially affected vehicles by looking for “KARR” or “SWDS” stickers on the driver-side window — a common dealership practice that now serves as a beacon for attackers.
The shared cryptographic key is the linchpin of the entire attack. In properly designed Bluetooth systems, each device is assigned a unique key during manufacturing or pairing, ensuring that compromising one device does not compromise others. Acrisure’s decision to use a single key across millions of modules means that once the researchers extracted that key — which they did through standard reverse engineering techniques — every device in the field became effectively identical from an authentication standpoint. An attacker can simply broadcast the correct authentication packet, gain access, and execute commands without needing to physically interact with the vehicle.
What Commands Can an Attacker Execute Over Bluetooth?
An attacker within Bluetooth range — approximately five yards, though directional antennas could extend this — can remotely unlock the vehicle’s doors, flash the headlights, and sound the horn. The most damaging capability, however, is the ability to prevent the engine from starting. The aftermarket module is wired into the vehicle’s ignition system, and a command sent over Bluetooth can disable the starter circuit. This means that even if a thief gains physical access through other means, the vehicle will not start unless the attacker can bypass or remove the module. For owners who have paid for the anti-theft service, this is supposed to be a feature; for the millions who have not, it is a hidden vulnerability that actively works against them.
It is important to understand what the attack cannot do. The researchers confirmed that the vulnerability does not allow the engine to be started remotely. Starting the engine would require physical presence inside the vehicle or exploitation of a separate system. But the unlocked doors and disabled ignition create a dangerous scenario: a thief who breaks a window or uses a relay attack on the vehicle’s own keyless entry system now finds the car already unlocked and, more importantly, immobilised in a way that prevents a quick getaway. The real risk is that an attacker unlocks the vehicle, removes or disables the aftermarket module (which requires dashboard disassembly but is feasible given time), and then uses the vehicle’s native ignition system to start it. The vulnerability effectively hands the thief the first step.
Location Data Exposure Compounds the Threat
During their investigation, the UC San Diego team made an additional disturbing discovery: publicly accessible databases expose location information associated with some vehicles equipped with KARR and SWDS systems. These databases, which are part of the normal operation of the fleet management and inventory tracking systems used by dealerships, leak the geographic positions of vehicles. For an attacker, this means they can identify potential targets remotely, cross-reference location data with the presence of the KARR or SWDS window stickers, and plan an attack from a distance before ever approaching the vehicle. The combination of Bluetooth unlocking capability and location data creates a powerful toolkit for targeted theft.
The researchers traced the origin of this project back to 2018, when they were initially scanning for Bluetooth-enabled credit card skimmers installed in gas pumps. During that routine scanning work, they began detecting previously unidentified Bluetooth devices that did not match any known consumer electronics profiles. Tracking these signals led them to the aftermarket automotive security systems, and a broader security analysis followed. The fact that the investigation began with skimmer detection and ended with a multi-million-vehicle vulnerability underscores how intertwined modern automotive security has become with consumer electronics, aftermarket installations, and supply chain oversight.
What Is a Replay Attack and How Does It Affect the Broader Market?
The UC San Diego team also examined similar aftermarket systems manufactured by Rockledge. In those systems, they identified what appears to be a replay attack vulnerability. A replay attack involves intercepting legitimate Bluetooth communications between an owner’s smartphone and the vehicle, recording those communications, and then replaying them to gain unauthorised access. This is a different attack vector from the shared key flaw found in Acrisure devices — it requires the attacker to be physically present during a legitimate pairing or unlock event to capture the data — but it represents a separate and significant vulnerability in the aftermarket security ecosystem.
Critically, Rockledge had not responded to the researchers’ disclosure when the study was published, meaning the team was unable to fully validate their findings or determine whether a firmware fix is forthcoming. The lack of a response from Rockledge raises questions about the company’s willingness to address security issues and about the state of vulnerability disclosure in the aftermarket automotive industry more broadly. While Acrisure acted relatively quickly — releasing a firmware update on July 20 — the uneven response across manufacturers highlights a fragmented security posture in an industry that handles access control for millions of vehicles.
Acrisure’s Firmware Update: What Owners Need to Know
Acrisure released a firmware update on July 20 that addresses the shared key vulnerability in KARR and SWDS modules. The researchers recommend that owners of affected vehicles install the update through the KARR mobile application, which is the standard method for configuring and managing these aftermarket systems. Physically removing the hardware is not a practical option for most owners, as doing so requires significant dashboard disassembly and modifications to wiring that is integrated with the vehicle’s ignition system. Attempting to remove the module without proper training could introduce new electrical problems, void warranties, or even render the vehicle inoperable.
For owners who are unsure whether their vehicle is affected, the first step is to check for the KARR or SWDS sticker on the driver-side window. If the sticker is present, the vehicle almost certainly contains the vulnerable hardware. Owners who did not purchase the optional anti-theft package at the time of sale may not have the KARR app installed on their phones, but they can download it from the Apple App Store or Google Play Store. Once the app is installed and paired with the module, the firmware update should be available as a standard over-the-air update. The process is straightforward, but it requires active action from the owner — a significant hurdle given that many owners do not even know the hardware exists.
One of the most troubling aspects of this vulnerability is the sheer number of affected vehicles combined with the low awareness among owners. Researchers estimate that the majority of the 2.2 million affected vehicles are currently driven by people who never paid for the security service, never installed the app, and never received any communication from the dealer about the hardware in their car. These owners are not only vulnerable to attack — they are also unlikely to learn about the firmware update or take the steps necessary to protect themselves. Dealerships, the original installers of these modules, have a responsibility to notify affected customers, but there is no regulatory requirement for them to do so, and vehicle title transfers complicate any notification effort.
How Did This Vulnerability Go Undetected for So Long?
The aftermarket automotive security industry operates largely outside the public scrutiny that applies to original equipment manufacturers. While automakers like Ford, Toyota, and Honda invest heavily in cybersecurity for their own infotainment and telematics systems, the aftermarket modules installed by dealers are often designed by smaller companies with limited security budgets and less rigorous testing. The KARR and SWDS modules, manufactured by Acrisure — a company whose primary business is insurance and financial services, not cybersecurity — are a clear example of this dynamic. The modules are designed for convenience and cost-effectiveness, not for resistance to determined attackers.
Furthermore, the vulnerability was invisible to most security researchers because these modules do not broadcast any standard identification that would alert a scanner to their presence. The UC San Diego team discovered them only by accident, while pursuing an entirely different investigation. This suggests that the true scale of aftermarket security vulnerabilities may be significantly larger than what is currently understood. If a cryptographic key shared across millions of devices can go unnoticed for years, what other shared secrets, hardcoded credentials, or backdoor commands might be lurking in the thousands of aftermarket modules installed in vehicles every day?
The Ripple Effects for Dealerships, Insurers, and the Used Car Market
The consequences of this vulnerability extend far beyond individual car owners. Dealerships that installed these modules may face liability questions, particularly if it emerges that they failed to disclose the presence of the hardware or did not inform buyers about the associated security risks. Insurance companies, which have been increasingly interested in telematics and anti-theft discounts, may need to reassess the risk profiles of vehicles equipped with aftermarket security systems. A system marketed as a theft deterrent that actually makes theft easier is a liability for everyone involved.
The used car market, where many of the affected vehicles now trade, faces a particular challenge. A 2017 Honda Civic that was originally sold in Southern California with a KARR module could now be on a used lot in Chicago, with a new owner who has no idea the module is installed. The KARR or SWDS sticker may have been removed during a repaint or window replacement, or it may have faded to illegibility. Without the sticker, even a determined buyer has no way to know whether the vehicle is affected unless they physically inspect the dashboard wiring — a task far beyond the capabilities of most consumers and even many mechanics.
In the long term, this incident may accelerate regulatory scrutiny of aftermarket automotive devices. The US National Highway Traffic Safety Administration was notified of the vulnerability before publication, and it is likely that the agency will examine not only the Acrisure modules but also similar products from other manufacturers. There is currently no federal requirement for aftermarket automotive security devices to undergo cybersecurity testing or certification, but that could change if incidents like this become more frequent. Europe’s UN Regulation No. 155, which requires automakers to implement cybersecurity management systems, already sets a precedent that could influence US policy.
What Should Owners Do Right Now?
For anyone who suspects their vehicle may be affected, the immediate steps are clear. Check for the KARR or SWDS sticker on the driver-side window. If the sticker is present, download the KARR mobile app, pair it with the module, and install the firmware update released on July 20. If the sticker is not present but the vehicle was purchased from a dealership in Southern California that offers KARR or SWDS systems — particularly Honda, Toyota, Mazda, Ford, or Jeep dealerships — it is worth contacting the dealership directly to ask whether the module was installed. Owners should also consider whether the vehicle exhibits any signs of aftermarket security hardware, such as a small LED indicator on the dashboard or unfamiliar Bluetooth devices listed in their phone’s pairing menu.
For owners who are unable or unwilling to go through the firmware update process, the only other option is to have the module physically removed by a qualified automotive electrician. This is more expensive and time-consuming than applying a software update, but it eliminates the vulnerability entirely. Given that the shared key allows any attacker to authenticate with any device, there is no benefit to delaying action. Every day that passes without the update is a day in which the vehicle is trivially unlockable by anyone with basic technical knowledge and proximity to the car.
Lessons for the Automotive and Technology Industries
The KARR and SWDS vulnerability is a textbook example of what happens when security is treated as an afterthought in product design. The decision to use a single cryptographic key across millions of devices is not a subtle engineering mistake — it is a fundamental failure to understand even the basics of authentication system design. That this decision was made by a company whose products control access to millions of vehicles is deeply concerning. It suggests that the aftermarket automotive security industry lacks the security engineering expertise that is now standard in sectors like banking, telecommunications, and cloud computing.
The broader lesson is that the automotive industry’s security perimeter extends far beyond what the automakers themselves control. Every aftermarket module, every third-party dongle, every dealer-installed accessory represents a potential attack surface. As vehicles become more software-defined and more connected, the number of these entry points will only grow. Automakers, dealers, and regulators must work together to establish minimum security standards for aftermarket devices, including mandatory disclosure requirements, vulnerability reporting programs, and the ability to push security updates to devices that are already in the field.
For the 2.2 million vehicle owners affected by this vulnerability, the immediate course of action is a firmware update through an app many of them do not have. For the industry, the path forward requires acknowledging that security cannot stop at the factory door. The aftermarket is where many of tomorrow’s automotive security challenges will emerge, and the KARR and SWDS incident should serve as a warning — not just about shared cryptographic keys, but about an entire ecosystem that has, for too long, operated without meaningful security oversight.