A Single Bluetooth Key Leaves 2.2 Million Cars Open to Remote Theft

Researchers at UC San Diego have found that at least 2.2 million cars on US roads carry a hidden aftermarket security device that can be remotely unlocked, tracked, and disabled by anyone with a Bluetooth-capable phone within about five yards. The flaw affects KARR and SWDS branded systems made by Acrisure, commonly installed by dealerships in Honda, Toyota, Mazda, Ford, and Jeep vehicles sold across Southern California since 2017, though resale has spread affected cars throughout the US, Canada, and as far as Japan.

The device sits under the dashboard on the driver's side and connects to a companion smartphone app over Bluetooth, letting owners lock and unlock doors, sound the horn, flash the lights, and immobilize the engine before the car starts — functions dealerships market as a paid anti-theft upgrade. The researchers found that every one of these devices ships with the same hardcoded authentication key. Once they extracted that single key, it granted access to every vehicle running the system, comparable to every lock in a product line sharing the same combination with no way to change it.

That design flaw means an attacker doesn't need to break a window to get into a car. Connecting to the device over Bluetooth and unlocking the doors is enough, after which commonly available locksmith tools can start the vehicle and drive it away. The researchers also found that public Bluetooth-tracking databases expose location data for vehicles running these systems, making it possible to locate specific cars remotely before ever approaching them.

Many owners have no idea the device is in their vehicle. Cars affected typically carry a small sticker reading "KARR" or "SWDS" on the driver's-side window, and the device stays active even when a buyer declines the paid upgrade at the dealership. A related product from a second manufacturer, Rockledge, was also found to carry weaknesses, though exploiting it requires an attacker to be physically present to intercept a legitimate connection first — a harder bar to clear than the Acrisure flaw.

Acrisure released a firmware patch on July 20, which owners must install manually through the KARR app; simply removing the hardware isn't practical, since the device's wiring runs directly into the car's ignition and onboard computer systems. The research team, who disclosed the vulnerability to manufacturers, automakers, and the National Highway Traffic Safety Administration before going public, is withholding the technical details of how they cracked the system to keep the method out of thieves' hands. They plan to present the full findings at DEF CON in Las Vegas on August 9 and at the USENIX Security conference in Baltimore on August 12.

Car owners who bought a vehicle in the affected regions since 2017 — even those who declined the anti-theft upgrade — are advised to check for a KARR or SWDS sticker and update the app-connected firmware as soon as possible.