Leading Off

2.2 Million Cars Share One Bluetooth Password. Your Dealer Installed It and Never Told You.

UC San Diego researchers cracked a dealer-installed anti-theft system that lets anyone with a phone unlock your doors, kill your engine, and track where you park. The fix takes two minutes. Here's how.

2.2 Million Cars Share One Bluetooth Password. Your Dealer Installed It and Never Told You.

Ninety-seven cars. That's how many vulnerable vehicles UC San Diego researchers counted during a single 20-minute drive near campus. They weren't driving fast. They didn't need special equipment. Just an Android phone running an app they'd built themselves.

Every one of those 97 cars could've been unlocked from five yards away. No broken window. No alarm. No evidence. A silent Bluetooth command, a click of the door handle, and the car is open.

The device responsible is called the KARR Security System. It's manufactured by Carlsbad-based Acrisure Protection Group and sold to dealerships across Southern California as an anti-theft and GPS tracking tool. Over 3,000 dealerships nationwide carry it. And here's the part that should keep you up tonight: you might have one in your car right now and not even know it.

At least 2.2 million vehicles are affected. Most were sold at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to the present. But resales have scattered these cars across the country, into Canada, and as far as Japan.

What KARR Is and How It Got Into Your Car

The KARR system is a small Bluetooth-enabled device wired underneath the driver's side of the dashboard. It connects to your car's computer system and can lock and unlock doors, honk the horn, flash the headlights, and kill the ignition so the car won't start. Dealers installed it on their lots as inventory protection before the vehicle was sold.

When you bought the car, the dealer probably offered the KARR system as a paid upgrade. Pay $500 to $1,500 and you'd get a smartphone app that lets you control your car remotely. Sounds useful.

But if you said no? The dealer left the hardware wired in anyway. They didn't remove it. They didn't disconnect it. They just didn't activate the subscription. The device stayed bolted under your dashboard, still connected to your car's electronic brain, still broadcasting a Bluetooth signal to anyone within range.

According to the UC San Diego research team, at least half of the 2.2 million owners with KARR hardware don't know it's there. If you bought a Honda, Toyota, Mazda, Ford, or Jeep from a San Diego County dealership since 2017, there's a real chance yours is one of them. That includes major local dealers like Mossy Toyota and Mossy Ford in Pacific Beach, though neither dealership has publicly commented on whether they installed KARR devices.

One Password for 2.2 Million Cars

The flaw is almost laughable in how basic it is. Every single KARR device ever installed uses the same authentication key. All 2.2 million of them. Professor Aaron Schulman, who led the UC San Diego research team, compared it to setting the password on every device to "1234" and making it impossible to change.

His team found that key by reverse-engineering the official KARR smartphone app. It was right there in the code. Once they had it, they built their own Android app that could impersonate the real KARR software and send commands to any KARR-equipped car within Bluetooth range.

Unlock the doors. Silently. No alarm.

Kill the ignition so the car won't start.

Honk the horn and flash the lights on every KARR-equipped car in a parking lot at the same time. The researchers called this one "mayhem mode."

And it gets worse. The KARR device broadcasts a Bluetooth signal while the car is running and for up to 10 minutes after you turn the ignition off. Even deactivated systems keep broadcasting. An attacker can remotely activate a deactivated KARR device before sending additional commands. The only warning you'd get? A brief horn honk and a flash of the headlights. Most people wouldn't think twice about it.

They Can Track You, Too

Every KARR device broadcasts a unique Bluetooth identifier. The UC San Diego team used a crowdsourced wireless signal database called WiGLE to estimate how many devices are deployed. But that same database stores historical location records for detected wireless signals. Someone with access could look up where a specific KARR device has been detected over time and build a picture of where the car parks regularly, when it's usually there, and what routes it takes.

That turns a car alarm into a tracking device.

How They Found It: Credit Card Skimmers Led to Car Hacking

The discovery started by accident. In 2018, Schulman and his students were hunting for Bluetooth-based credit card skimmers hidden inside San Diego gas station pumps. They kept picking up a Bluetooth signal they couldn't identify. It was everywhere.

It took years to figure out what it was. By 2024, the team had pieced it together: that mystery signal was coming from KARR devices installed in cars at nearly every major dealership in the county. And once they started digging into how the system authenticated connections, they found the entire thing was built on a single shared key.

Schulman described the moment to the San Diego Union-Tribune. He and his students were the only people in the world who knew how to unlock any KARR-equipped car with a phone. He lost sleep over it.

So he called KARR's customer service line. A few days later, the company's security team came to the UC San Diego campus and watched one of Schulman's students hijack a car using their own technology. They spent an hour at a whiteboard mapping out a fix. According to Schulman, Acrisure implemented what they discussed.

18 Months to Patch

That whiteboard session sounds productive. But look at the timeline. Schulman's team reported the vulnerability to Acrisure in January 2025. The firmware patch went live on July 20, 2026. Eighteen months. Every KARR-equipped car sat wide open while the company worked on an update.

And the patch only arrived weeks before Schulman's team is scheduled to present their full research at DEF CON in Las Vegas on August 9 and the USENIX Security Symposium in Baltimore on August 12. That's standard practice in the security research world. The threat of public disclosure at a hacker conference is what finally forced the company's hand. The paper is titled "BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems." When those presentations happen, the technical details go fully public.

Acrisure's official response? They called the attack "highly complex" and said it presents "low risk under real-world conditions."

The researchers don't agree. One UCSD professor called it probably the worst car-hacking vulnerability ever documented. And Wired magazine filmed a demonstration where the team used the exploit plus a commonly available locksmith tool to get into and start a car in minutes. "Highly complex" is doing some heavy lifting in that company statement.

Does Your Car Have a KARR System?

Check three things right now.

1. Your driver's side window. Look for a small sticker that says "KARR" or "SWDS" (SouthWest Dealer Services). Most cars sold at Southern California dealerships from 2017 on will have one of these if the system was installed.

2. Under your dashboard on the driver's side. Look for a small button with a blinking light mounted to the underside of the dashboard panel. That's the KARR device.

3. Call your dealer. If you bought a Honda, Toyota, Mazda, Ford, or Jeep from a Southern California dealership since 2017, call and ask whether they installed KARR or SWDS hardware on your vehicle. Don't accept a vague answer.

If you bought a used car from anywhere in the country, check all three. These vehicles are circulating through the secondhand market nationwide.

How to Fix It: The Two-Minute Firmware Update

KARR released a firmware update on July 20, 2026. You need to install it yourself. Your dealership can't push it to your car remotely. Neither can the manufacturer. You have to sit in the driver's seat with your phone and do it manually.

The process is different depending on whether you're a paying KARR subscriber or not. Both paths take about two minutes.

If You Have an Activated System (You Pay for KARR)

You already have the KARR Security app on your phone. Open it, log in, select your vehicle, tap Settings in the bottom right corner, scroll to "Check for Updates," and follow the prompts. If your firmware is current, the app tells you. You're done.

If You Have a Non-Activated System (Most People)

This covers the majority of affected drivers. Follow these steps exactly:

1. Go to your car and sit in the driver's seat.
2. Turn on Bluetooth on your phone.
3. Download the KARR Security app (free on App Store and Google Play).
4. Open the app.
5. Tap "Customer Service" at the bottom of the app screen.
6. Tap "Firmware Update."
7. Accept Bluetooth and location permissions when prompted.
8. Enter the last 8 digits of your VIN number. You'll find it on a plate at the base of your windshield on the driver's side, or on the sticker inside your driver's door jamb.
9. Turn your ignition to the ON position. Don't start the engine. If you have push-button start, press the button without your foot on the brake.
10. Wait 5 seconds, then tap OK in the app.
11. Turn the ignition off.

Firmware update complete. The entire process takes less than two minutes, and it closes the Bluetooth backdoor that may have been sitting in your car for up to nine years.

For additional help, you can also follow the step-by-step instructions and video tutorials on KARR's website. And if you run into trouble, KARR's customer service line is 1-800-395-5277, available 24 hours.

What This Means for San Diego County

San Diego is ground zero. KARR's parent company Acrisure is headquartered in Carlsbad, and Southern California dealerships were the primary installers from 2017 onward. That means San Diego County likely has one of the densest concentrations of affected vehicles in the country.

Think about what that looks like in practice. The researchers found 97 vulnerable cars in 20 minutes near UCSD. Scale that across the parking garages downtown, the beach lots in Pacific Beach, the overnight streets in Coronado and La Jolla, the shopping centers in Del Mar. Thousands of cars across San Diego County are sitting right now with a hackable Bluetooth device wired into their dashboards.

If you're a car owner in San Diego and you've bought or leased from a Honda, Toyota, Mazda, Ford, or Jeep dealer since 2017, this isn't something to put off. Go to your car today. Look for the sticker. Download the app. Run the update.

Want the Device Removed Entirely?

The firmware update closes the vulnerability, but if you'd rather have the KARR hardware pulled out of your car completely, know that it's not a simple job. According to UCSD researcher Yibo Wei, removing the device requires opening up the dashboard and cutting and reconnecting wires that are tied into the car's computer and ignition system. It's a job for a qualified mechanic, not a weekend DIY project.

San Diego Lineup lists trusted auto repair shops and mechanics across the county. You can find automotive service providers in North Park, Hillcrest, Pacific Beach, La Jolla, Del Mar, and Coronado. Shops like T P Auto Repair in North Park, Coastal Auto Repair in Pacific Beach, Del Mar Automotive, Hillcrest Auto Repair, Mission Hills Automotive, and Family Auto Service in La Jolla all handle electronic and electrical work. Call ahead, describe the situation, and ask if they have experience with aftermarket alarm removal.

The Bigger Problem Nobody's Talking About

KARR isn't the only company making these aftermarket systems. UCSD researchers also flagged Rockledge, another car security and insurance company, as potentially vulnerable. Rockledge's devices use a different authentication method that's harder to crack, but the company hadn't responded to the researchers' disclosure as of publication.

The real issue goes beyond one company. Dealer-installed hardware lives outside the automaker's normal security and update pipeline. Toyota can push a software update to your infotainment system. But Toyota has no idea there's a third-party Bluetooth device bolted to your dashboard, and they can't patch it. Neither can your insurance company. The burden falls entirely on you to find out the device exists, download an app you've never heard of, and fix it yourself.

And most owners don't know it's there.

The UCSD team is pushing for a simple fix going forward: any time a new smartphone connects to one of these Bluetooth-based security systems, the car should require a physical interaction inside the vehicle, like pressing a button, to confirm the connection. That would stop the remote impersonation attack cold. Whether manufacturers actually adopt that standard is another question.

For now, check your car. Run the update. And tell everyone you know who bought a car in Southern California since 2017 to do the same thing today.