A Bluetooth security vulnerability affecting Karr dealer-installed alarm systems could allow hackers within Bluetooth range to unlock vehicle doors, disable ignition, and send other commands to affected cars. The issue impacts technology installed in approximately 2 million vehicles across the United States, including some cars whose owners may not realize the system is present.
Researchers Identify Bluetooth Vulnerability
Researchers at the University of California San Diego discovered a flaw in Karr’s dealer-installed alarm system that could enable attackers to communicate with affected vehicles over Bluetooth.
According to the researchers, the vulnerability could allow malicious users to unlock doors, disable a vehicle’s ignition, and issue other commands. The findings were first reported by Wired.
Firmware Update Is Available
Karr was notified of the security issue before it became public and has since released a firmware update designed to address the vulnerability.
The update can be installed through Karr’s companion smartphone application, which is available for download whether or not the vehicle owner is a paying subscriber.
Owners who are unsure whether their vehicle is equipped with a Karr system can look for stickers labeled “Karr” or “SWDS” on the driver’s-side window.
Karr Says Risk Is Low
Karr said it plans to work with dealerships to notify owners of affected vehicles.
In a statement to Wired, a company spokesperson said, “The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions. Nevertheless, we responded promptly and developed a firmware update to address the issue.”
According to the report, the firmware patch was released 18 months after the company was informed of the issue.
Researchers Dispute Company’s Assessment
The UC San Diego researchers disagreed with Karr’s characterization of the risk. One professor described the issue as “probably the worst” car hacking threat to date.
The researchers also demonstrated to Wired how a Karr-equipped vehicle that had not received the update could be manipulated, provided the attacker had the necessary software.
The report also notes that the alarm system’s Bluetooth radio remains active for 10 minutes after the vehicle is turned off, extending the period during which the system could potentially be accessed.
Why So Many Vehicles Have Karr Systems
Karr works with more than 3,000 dealerships nationwide. Some dealers install the company’s hardware before vehicles are sold so inventory can be tracked as a loss-prevention measure while cars remain on dealer lots.
At the time of purchase, customers may be offered the option to pay an ongoing fee to use the alarm system’s security features. However, if buyers decline the service, the hardware may remain installed unless they specifically request its removal, and not every dealership may agree to remove it without difficulty.
Issue Highlights Dealer-Installed Connected Hardware
The reported vulnerability has drawn attention to dealer-installed connected hardware that can remain in vehicles even when owners have not chosen to subscribe to its services.
Karr has released a firmware update to address the Bluetooth vulnerability and says it intends to notify owners of affected vehicles through its dealership network.








