Two million drivers are sitting in cars that can be unlocked with a smartphone.
It is not a movie plot. It is real. The culprit is a little box called the KARR Security System. It plugs into your car’s computer. It was meant to stop theft. Now it invites it.
Cybersecurity experts are calling this one of the worst Bluetooth vulnerabilities in cars seen in years. Why? Because the device is still running. Even if you never paid for it. Even if you don’t know it’s there.
Which cars have the KARR device installed?
The KARR system started as a dealership tool. Lots wanted to track inventory. They wanted to stop cars from vanishing off the lot. So they installed the device. It connects to the vehicle’s key security functions. It talks to an app via Bluetooth.
When the car sold, dealers tried to sell the access. Some people bought it. Most didn’t.
But the hardware stayed.
If you bought a Honda, Toyota, Mazda, Ford, or Jeep in the last nine years, you might be at risk. The cars have moved around. Some are in Canada. Some in Japan. If you bought used, you probably didn’t get the memo.
Look for a clue. A “KARR” sticker on the window. Or one that says SWDS (Southwest Dealer Services). Check under the dashboard. A small blinking button? That’s the device.
Do not rip it out. It is wired into important systems. Pulling it wrong breaks things.
How the KARR Bluetooth hack actually works
The flaw is stupid. Simple. Every single KARR device uses the same authentication key.
Imagine a password of “1234”.
If you hack one device, you have the key to all of them.
Researchers from the University of California, San Diego (UCSD) proved it. They built a custom app. They pinged the device over Bluetooth. No physical access needed. Just wireless.
With a few taps, they could:
– Unlock doors.
– Honk the horn.
– Flash headlights.
– Prevent the engine from starting (if it was off).
It sounds harmless. Flashing lights is annoying. Not dangerous.
It is.
The hack does not start the engine. A thief can’t just drive away using their phone. But they don’t need to.
They walk in. Quietly. No smashed window. No prying door. They sit inside. Then they use “locksmith key-cloning” tools. These are cheap. Available online. They extract the car’s digital key from the computer. Then they drive off.
Stefan Savage, a professor at UCSD, told Wired this is the worst car hacking threat he has seen. He knows what he is talking about.
Jerry Yu, a researcher on the project, said thieves could just connect remotely.
“Instead of smashing a window to get access, they simply connect via Bluetooth… and make it unlock car doors.”
Why haven’t I received a software update?
This is the frustrating part.
UCSD told Acrisure Protection Group about the hole in January 2025. The fix came out on July 20, 26.
That is a long time.
Acrisure owns the KARR brand. They say the risk is “low” in real world conditions. They claim no one has stolen a car this way yet. They call the hack “complex.”
Complex enough to require a custom app. Not complex enough to leave two million cars exposed for months.
Active users got an alert. They logged in. They updated.
The rest? You have to look for it.
Download the KARR app. Enter the last eight digits of your VIN. Even if you never used the service. The update works. You need to install it.
Is it worth the hassle to check your car?
Maybe.
Maybe not.
Modern cars are computers. We knew this. They are “smartphones on wheels.” That brings benefits. Over-the-air updates fix recalls in hours. No trip to the shop. Subscriptions unlock heated seats. Extra horsepower. It is convenient.
It is also risky.
Every connection is a door. Every update is a patch for a hole someone else found. We treat our laptops this way. We treat our phones this way. We forget the car.
The KARR hack shows what happens when we forget. A device meant for safety becomes a backdoor. A shared key becomes a master key.
Two million drivers. One update.
Most of them won’t know they need it until it is too late. Or until a window breaks. Or a horn honks at 2 a.m. for no reason.
You have the app. You have the VIN.
Do you really want to find out if you are vulnerable?
Or are you just going to keep driving?




















