Security Flaw in Dealer-Installed Systems

A significant security vulnerability has been uncovered in automobile protection systems manufactured by Acrisure, specifically the KARR and SWDS models. These devices, often marketed as anti-theft and vehicle tracking solutions, contain a critical flaw that grants attackers the ability to manipulate vehicle functions remotely using a Bluetooth connection.


Scope of the Vulnerability

Research conducted by the University of California San Diego (UCSD) indicates that approximately 2.2 million vehicles are potentially at risk. While the majority of these cars were sold through dealerships in Southern California since 2017—spanning brands such as Toyota, Honda, Ford, Mazda, and Jeep—experts warn that the reach may be much broader due to the secondary vehicle market. Furthermore, investigators discovered a publicly accessible database that contains sensitive information regarding the specific vehicles equipped with these security units.


How the Bluetooth Attack Works

The security devices are identifiable by a "KARR-SWDS" sticker on the driver-side window, with the hardware typically installed beneath the dashboard. Under normal circumstances, users operate these systems via a mobile application that links to the car via Bluetooth. The app allows for various controls, including:

  • Locking and unlocking doors
  • Activating the horn
  • Flashing the headlights
  • Disabling the vehicle's ignition

The core of the issue lies in the system's architecture. The researchers discovered that every KARR security unit utilizes the same hardcoded security key. As Yibo Wei, a PhD candidate at UCSD and co-author of the study, noted:

"Removing the devices is not trivial. You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car's computers and ignition system."


The Difficulty of Mitigation

The situation is compounded by the fact that the hardware remains active even if the owner has not subscribed to the service. Neither the Bluetooth functionality nor the master key can be easily changed by the user. Co-author Jerry Yu highlighted the severity of the threat, stating:

"Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors."


In response to these findings, KARR has stated that the issue is limited to specific units equipped with certain Bluetooth components. The company claims to have released a firmware update to address the security concern.