Millions of cars could be tracked and unlocked by a hidden security flaw

| July 23, 2026
Cars lined up at a dealership

A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed.

The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California.

Aftermarket car alarms are a strange corner of the auto industry. Dealers install them in your car before you ever see the vehicle, then try to sell you the subscription afterward. Say no and the hardware still stays put. According to researchers at the University of California San Diego, KARR systems are installed in about 2.2 million American vehicles, and around half of owners don’t even know they’re there.

The research team, led by computer science professor Aaron Schulman, investigated the system and found a single design flaw repeated across nearly a decade of installations.

Every KARR device shares the same authentication key, and it’s stored in plain text inside the KARR smartphone app. Extract it once and you can communicate with any KARR-equipped vehicle made since 2017. That is what the researchers did.

What the attack actually does

Standing within about five yards of a target vehicle, an attacker using the researchers’ proof-of-concept tool can unlock the vehicle and even disable its ignition, potentially leaving a driver stranded. The only outward sign is a brief beep and flicker when the command is sent. The owner receives no alert.

The location tracking issue is arguably even more concerning. KARR units continuously broadcast Bluetooth identifiers, so crowdsourced radio databases like WiGLE have been logging their locations for years. Feed a device’s identifier into WiGLE and you can build a picture of where that car has been parked. It’s a stalker’s dream. The researchers also demonstrated a “mayhem” mode that triggers horns and lights across multiple parked vehicles at once.

Owners who declined the paid service and assumed the hardware was inactive were wrong. According to the researchers, dormant units accept a single Bluetooth wake-up command before exposing the same functionality.

Eighteen months, one conference deadline

UC San Diego disclosed the flaw to Acrisure in January 2025, but a firmware fix did not arrive until July 20, 2026—roughly 18 months later, and only weeks before the team was due to present its findings at the DEF CON hacker conference next month. Acrisure has publicly characterized the real-world risk as low.

Compare that with Subaru’s response to a similar connected-car flaw disclosed last year. Researchers found that Subaru’s Starlink admin portal could hand over any car to anyone armed with a license plate and the owner’s last name or email. From there, someone could unlock the doors and start the engine—or dig into a year of location history accurate to within five meters.

The underlying problems there were an insecure password-reset endpoint and weak protection against two-factor authentication (2FA) bypass. Subaru fixed the issues within 24 hours.

The fix can’t reach half its audience

The awkward part here is that the patch ships through the KARR companion app, which only paying customers would ever have downloaded. The researchers estimate that at least half of car owners with these devices installed didn’t ask for it, meaning that there’s little chance they’ll run the app or update the firmware. Roughly a million people cannot patch what they do not know exists. This includes many folks who might have purchased a KARR-equipped vehicle on the second-hand market.

How to check your car

Look for a KARR sticker on the driver-side window, or one reading “SWDS” for SouthWest Dealer Services (an Acrisure subsidiary). Then check the underside of the dashboard for a small button with a blinking light, according to Wired. If you find one, download the KARR app and apply the firmware update—even if you never knowingly signed up for the alarm in the first place.


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

About the author

Danny Bradbury has been a journalist specialising in technology since 1989 and a freelance writer since 1994. He covers a broad variety of technology issues for audiences ranging from consumers through to software developers and CIOs. He also ghostwrites articles for many C-suite business executives in the technology sector. He hails from the UK but now lives in Western Canada.