A study by University of California, San Diego (UCSD) researchers has uncovered a critical security flaw in an aftermarket car alarm system installed in over two million US vehicles. Dubbed the KARR Security System, this device, typically installed by dealers and hidden from owners, can be hacked to unlock cars, disable alarms or even render them immobile.
The KARR Security System is vulnerable to Bluetooth-based commands that allow hackers within range to control it without the car owner’s knowledge. This poses a significant risk, especially as many owners were not aware they had purchased such a device and thus never installed any security updates for it.
“We’re trying to get the word out that you need to check your car for this device and manually patch it now,” said Aaron Schulman, the UCSD computer science professor leading the research. The firm behind KARR, Acrisure Protection Group, has since rolled out a firmware update but admits it took nearly 18 months to address the issue.
The delay in addressing the flaw raises serious concerns about the broader implications of such vulnerabilities. As car technology advances, so do the risks associated with cyber security gaps that are often hidden from vehicle owners until it’s too late. The UCSD team warns that the KARR system could be among the worst car hacking threats ever discovered, potentially affecting millions of vehicles.







