UC San Diego Researchers Expose Critical Flaw in Two Million US Vehicles
A firmware patch from Acrisure Protection Group arrives 18 months after the vulnerability was reported, leaving millions of drivers exposed to theft and sabotage.

Security researchers at the University of California San Diego have identified a severe vulnerability in the KARR Security System, an aftermarket car alarm installed in more than two million vehicles across the United States. The flaw allows any hacker within Bluetooth range to silently unlock vehicles, disable ignitions, track locations, and trigger horns or lights. The device, often left in cars even when buyers decline the feature, remains active and beaconing Bluetooth signals for up to 10 minutes after the car is turned off.
The vulnerability stems from a single authentication key shared across all KARR devices, which researchers found embedded in the KARR smartphone app’s code. Graduate researcher Jerry Yu identified the security flaw in 2024 as part of a summer project, building a homemade app that could spoof radio commands to activate the device. The team demonstrated that this exploit could unlock cars at stop lights, paralyse parked vehicles, and track historical locations using the WiGLE database.
Acrisure Protection Group, the manufacturer, has released a firmware update to patch the vulnerability, though the update took nearly 18 months to deploy after the flaw was reported to the company. The patch was rolled out shortly before planned presentations at the Defcon and Usenix security conferences. A spokesperson for Acrisure Protection Group stated that the vulnerability presents a low risk under real-world conditions, but researchers argue the ease of exploitation contradicts this assessment.
Car owners can check for the device by looking for a KARR sticker on the driver-side window or a small button with a blinking light under the dashboard. Those who already have the KARR Security smartphone app installed should receive an alert about the firmware update. Users without the app must download it, connect to the vehicle's alarm, and manually initiate the update through the customer service menu.
Stefan Savage, a UC San Diego professor not involved in the KARR research, described the flaw as “probably the worst” car hacking threat ever discovered due to its pervasiveness and the disconnect between owners and the supply chain. The device is particularly common in Southern California but has been found across the US and in other countries, leaving drivers unaware of the security risk in their vehicles.
