Owners of roughly 2.2 million vehicles sold through Southern California dealerships since 2017 need to check for a hidden Bluetooth vulnerability that could let a nearby attacker unlock their car doors and prevent the engine from starting. The flaw resides in dealer-installed KARR and SWDS anti-theft systems manufactured by Acrisure Protection Group, and the company released a firmware update on July 20, 2026, to close the security gap. Here’s what happened, who is affected, and exactly how to apply the fix.
The Bluetooth Flaw That Turned a Security Feature Into a Risk
Researchers at the University of California San Diego found that the KARR and SWDS systems all rely on a single shared cryptographic key for Bluetooth authentication. Once an attacker extracts that key—from one device, a mobile app, or through reverse engineering—they can communicate with any vulnerable system within Bluetooth range, roughly five yards. The compromised functions include locking and unlocking doors, activating the horn and lights, and, critically, engaging the engine immobilizer to prevent the vehicle from starting.
“Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors,” said Jerry Yu, co-author of the UC San Diego study. The immobilizer cannot stop a running engine, but it can leave a car stranded before a trip begins.
The researchers also discovered publicly accessible databases containing location information for vehicles equipped with these systems, which could make it easier for attackers to find and target specific cars. The full paper is set for release in August, but the team disclosed the critical details to enable a quick response.
Is Your Car Affected? How to Check
The vulnerable systems were installed primarily on vehicles from Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 onward. However, because vehicles get resold and moved, affected cars may now be anywhere in the United States, Canada, or even Japan. Owning one of those brands does not guarantee the system is present—the installation was a dealer add-on, not a factory feature.
Look for these telltale signs:
- A “KARR” or “SWDS” sticker on the driver-side window.
- A small button or LED indicator under the dashboard, near the steering column.
- Purchase paperwork or dealer documents mentioning KARR, SWDS, anti-theft, or vehicle protection packages.
- A vehicle history that traces back to a Southern California dealership, especially if it was originally sold there.
If you spot the sticker or button, assume the system is installed. Do not attempt to remove or disconnect any components yourself. “Removing the devices is not trivial,” warned Yibo Wei, a UC San Diego PhD candidate and paper co-author. “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”
What the Vulnerability Can and Cannot Do
It’s important to separate the real risks from Hollywood scenarios. What’s possible:
- Unlocking doors without a key or fob.
- Triggering the horn and lights, creating a nuisance or a distraction.
- Preventing the engine from starting, which could disable the car for a legitimate owner while enabling a thief to prepare for theft after gaining access.
What’s not possible:
- Remote steering, braking, or acceleration.
- Taking over a moving vehicle.
- Attacks over the internet—Bluetooth range limits the attacker to physical proximity.
That proximity is still a significant threat. Parking lots, driveways, and street parking are all potential attack zones. And because the system remains active even if the vehicle owner never paid for or activated the subscription service, millions of drivers may be completely unaware they have a vulnerable device buried in their dashboard.
The Fix: How to Apply the Firmware Update
Acrisure has issued a firmware update that replaces the shared key with a more secure authentication mechanism. The company’s KARR Security support page provides step-by-step instructions, and the process is straightforward once you confirm your vehicle is affected.
For Owners Who Activated the KARR Service:
- Download or open the KARR Security app on your smartphone.
- Connect to your vehicle’s system via Bluetooth as you normally would.
- Go to the app’s settings and select “Check for Updates.”
- Follow the on-screen prompts to download and install the firmware update.
- Wait for confirmation that the update is complete.
For Vehicles Where the System Was Never Activated:
Even if you declined the subscription at purchase, the hardware is still installed and can be updated. Acrisure’s support page says you can still use the app to verify your vehicle identification number (VIN) and apply the update.
1. Download the KARR Security app from your phone’s app store.
2. Use the in-app customer service feature to verify your VIN.
3. Once verified, follow the instructions to check for and install the update.
4. Ensure the app confirms the update is successful.
Important Precautions:
- Perform the update while you are physically with the vehicle, preferably in a safe location.
- Do not use any third-party apps or tools claiming to patch the system—stick to the official KARR Security app.
- If the app cannot identify your system, contact KARR customer support at 800-395-5277 or consult the selling dealer.
- Keep a screenshot or confirmation of the update in case you need to show it when selling the car.
How a Trusted Dealer Add-On Became a Security Nightmare
Dealerships often pitch aftermarket anti-theft systems as extra protection and convenience, bundling them into financing packages. KARR systems, specifically, offer features like remote lock/unlock, vehicle location, and inventory management for dealers. But the very connectivity that makes these features possible introduced a textbook security failure: using the same password for every device.
In cybersecurity terms, this is a “hardcoded shared secret” problem, common in early IoT devices. Once that secret is extracted from one unit, every other unit using it is compromised. Unlike your phone’s operating system, which receives regular patches, embedded car accessories often sit unmaintained for years. This incident underscores the urgent need for automotive aftermarket devices to adopt unique per-device credentials, secure pairing requirements, and robust over-the-air update mechanisms.
What to Watch Next
The looming question is adoption: a patch only protects cars whose owners know about it and apply it. With millions of vehicles potentially affected and many owners oblivious, the risk will persist until dealerships, automakers, and regulators step up outreach. In the longer term, expect increased scrutiny on dealer-installed electronics. The UC San Diego researchers recommend that any Bluetooth-connected car system require a physical button press inside the vehicle to pair a new phone—a simple defense that could have prevented this whole mess.
For now, if you own a car purchased from a Southern California dealer in recent years, check your windows and dashboard. Applying the firmware fix takes minutes and closes a door that should never have been left open.