Millions of US Cars Have a Hidden, Hackable Alarm Device That Owners Need to Patch Now

A security flaw in an aftermarket car alarm installed in more than 2 million vehicles across the United States allows hackers to remotely unlock cars, track them, disable their ignitions, and leave drivers stranded — and most owners don’t even know the device is there.

Researchers at UC San Diego disclosed the vulnerability in July 2026, identifying the affected device as the KARR Security System, made by Acrisure Protection Group. The Bluetooth-enabled alarm can be exploited by anyone within Bluetooth range, allowing them to silently unlock the vehicle, silence its alarm, trigger the horn or lights, or shut off the ignition entirely.

The KARR alarm is typically installed by car dealerships — not manufacturers or buyers — to deter theft on dealer lots. When a vehicle is sold, the device is usually left in place even if the buyer declines to pay for it as an optional feature. UC San Diego estimates that at least half of car owners with the device installed never requested it and are unaware it exists.

“This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars,” said Aaron Schulman, the UC San Diego computer science professor who led the research. “It’s designed to make cars more secure, but ultimately it’s created a vulnerability that needs to be patched immediately across millions of vehicles.”

Acrisure Protection Group released a firmware update on the same day the research was disclosed. Car owners who already have the KARR Security smartphone app installed should receive an alert about the update. Those without the app will need to download it for Android or iOS, connect it to the device, and navigate to “customer service” then “firmware update.”

To check whether a vehicle has the device, owners can look for a KARR or “SWDS” (SouthWest Dealer Services) sticker on the driver-side window, or a small button with a blinking light on the underside of the dashboard. The researchers note that while the device is most common among dealers in Southern California, affected vehicles have been found across the US and in other countries.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top