Security researchers are urging vehicle owners to update certain dealer-installed aftermarket alarm systems after finding a Bluetooth weakness they estimate may affect more than 2 million vehicles.
A University of California San Diego team studied KARR Security System devices commonly installed by dealerships. The researchers found that affected units relied on a shared authentication secret. A nearby attacker within Bluetooth range could potentially unlock doors, silence an alarm, flash lights, sound the horn or disable the ignition so a stopped vehicle could not restart. The reported technique could not start or drive the vehicle.
Acrisure Protection Group, which sells the systems, released a firmware update July 20. The company described the attack as complex and a low risk under real-world conditions, but owners should still install the patch promptly.
People who use the KARR mobile app may receive an update notice. Owners who are unsure whether their car has the equipment can look for KARR or SWDS paperwork or a small blinking button beneath the dashboard, then contact the selling dealer or official KARR support. Do not cut or remove wiring without professional guidance because the module may be connected to the ignition and other vehicle systems.
Firmware should be obtained only through the official app, dealer or manufacturer support channel. Avoid unofficial downloads or online instructions that claim to remove the device.
The research was summarized by UC San Diego via Newswise and reported by Wired. This report omits exploit details and focuses on the protective update.
