A new study from the University of California San Diego found that at least 2.2 million vehicles could be more vulnerable to theft because of a dealer-installed anti-theft device. Researchers said an attacker within Bluetooth range could connect to affected devices and unlock vehicle doors, raising concerns about the security of technology intended to prevent theft.
Dealer-Installed Anti-Theft Device at the Center of the Study
Modern anti-theft technologies, including engine immobilizers, have helped reduce vehicle theft. Ford also offers an advanced remote start-blocking feature known as Start Inhibit.
Despite those protections, the study found that certain dealer-installed anti-theft devices may create a different security risk. Vehicle owners can check for the words “KARR” or “SWDS” on the driver’s-side window to determine whether their vehicle may be equipped with one of the affected systems.
Shared Authentication Key Affects Millions of Vehicles
According to the researchers, all KARR-SWDS devices rely on the same authentication key, making millions of vehicles potentially vulnerable.
Most of the devices were installed by dealerships in Southern California. However, researchers said owners outside the region should also be aware because affected vehicles have been resold throughout the United States, Canada, and Japan.
The study states that most affected vehicles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California beginning in 2017.
Researchers said they intentionally withheld the technical details of the attacks to reduce the risk of the information being used for criminal activity.
Firmware Update Released for KARR-SWDS Devices
Acrisure, the company behind the KARR-SWDS devices, released a firmware update on July 20 to address the vulnerability.
Owners must install the update through the KARR app. The researchers also reported that similar devices manufactured by Rockledge may be vulnerable, although they appear more difficult to attack. They said those findings could not be validated because Rockledge had not responded to their disclosure.
Why Owners Should Check Their Vehicles
Dealerships typically install these devices to help manage inventory and reduce theft before later offering them to customers as paid upgrades with smartphone connectivity.
The study noted that even when buyers decline the upgrade, the device may remain installed, active, and vulnerable. Researchers therefore advise owners to check for “KARR” or “SWDS” branding and install the available firmware update to reduce the risk of theft.
The report also notes that connected-vehicle technology has faced legal scrutiny, citing a separate proposed class action alleging that Toyota collected and shared drivers’ data without their consent.
Researchers Say Security Improvements Are Needed
The researchers emphasized that the findings do not mean these devices are inherently flawed. They said the systems can still provide benefits, including real-time security alerts, GPS-based theft recovery, and smartphone controls.
However, the study concludes that manufacturers may need stronger security measures to prevent attackers from exploiting these connected features.
The researchers said they will present additional details at DEF CON in Las Vegas on August 9 and at the USENIX Security Symposium in Baltimore, Maryland, on August 12.








