💛 A quick favor, if you've got a second.
We're really happy that you chose to read one of our stories and sincerely hope you'll stick around to read more. We took our paywall down — for now — but that won't last forever, and when the gate goes back up, we'd love for you to already be on the inside.
It's free. So please enter your email here and don't forget to like and follow us on all of your favorite Social Media platforms!

A significant security weakness has been identified in aftermarket vehicle protection systems installed by dealerships across the United States. Researchers at UC San Diego uncovered a Bluetooth vulnerability affecting approximately 2.2 million vehicles equipped with KARR or SWDS security devices, which are sold through participating dealers rather than installed at the factory.
The flaw allows an attacker positioned within roughly five yards of a vulnerable vehicle to connect via Bluetooth and execute commands that compromise vehicle security. Potential attacks include unlocking doors, disabling alarms, honking the horn, flashing headlights, and preventing engine ignition in parked vehicles. However, the vulnerability alone cannot start an engine or disable a running vehicle, according to researchers.
KARR systems are aftermarket security products offered through dealerships nationwide and may include alarms, GPS tracking, remote controls, or ignition-disabling features. Southwest Dealer Services operates under several brand names including KARR Security, KARR Fusion, KARR BT, and S.W.A.T. Dealer. The devices typically sit beneath the driver-side dashboard and communicate with smartphone applications through Bluetooth Low Energy technology.
The root cause stems from affected devices relying on identical, unchangeable authentication keys for Bluetooth communication. Once researchers recovered this shared key, they could command vulnerable devices to execute unauthorized functions. Additionally, the devices broadcast recognizable Bluetooth signals that could be tracked using historical databases, raising privacy concerns beyond vehicle theft risk.
UC San Diego researchers found the devices most frequently in vehicles sold through Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California since 2017. However, KARR partners with more than 3,000 dealerships nationwide, meaning devices could appear in vehicles of various makes and models depending on where they were sold.
A complicating factor involves dealerships that installed hardware even when buyers declined the security service. Vehicle owners may possess an active vulnerability without purchasing or activating KARR service, and many remain unaware the equipment exists inside their vehicles.
KARR released a firmware patch on July 20, 2026, one day before UC San Diego publicly disclosed the vulnerability. Vehicle owners with activated systems can apply updates through the official KARR Security app. Those with inactive systems can still access updates using their vehicle identification number as a validation method.
To determine whether a vehicle contains a KARR device, owners should check for branded stickers on driver-side windows, inspect the lower dashboard area with a flashlight, review purchase and service documentation, and contact the original selling dealership with their VIN. KARR offers support at 800-395-5277 or through its official application available on Apple App Store and Google Play Store.
KARR Security stated that while the vulnerability is complex and presents low real-world risk, the company responded promptly to address the issue. The company reported no documented cases of the vulnerability being exploited in actual vehicle theft incidents.
Removing the device without professional assistance is not recommended, as it may require disconnecting components connected to ignition systems or vehicle computers. Improper removal could prevent vehicles from starting or disable factory security features. Professional automotive electrical technicians should handle deactivation or removal requests.
Disabling Bluetooth on smartphones, deleting the KARR app, or using Faraday pouches will not resolve the vulnerability. The KARR module operates independently from factory infotainment systems and requires direct firmware updates or physical removal. Vehicle owners should install the available firmware patch immediately and consider additional security measures such as steering wheel locks, GPS trackers, or improved parking practices in well-lit, visible locations.
More Stories
Packers Running Back Josh Jacobs Placed on NFL Commissioner’s Exempt List Following Domestic Arrest
Federal Prosecutors Convene Special Grand Jury to Investigate D.C. Schools’ Attendance and Graduation Practices
Denver Broncos Linebacker Jonathon Cooper Placed on Commissioner’s Exempt List Amid Domestic Violence Charges