A critical security flaw in the KARR Security System, an aftermarket car alarm device, affects approximately 2.2 million vehicles, primarily sold through dealerships in Southern California. This flaw allows potential attackers to unlock and disable the ignition of these vehicles using a shared authentication key stored in plain text within the KARR app. Additionally, the devices can continuously broadcast Bluetooth identifiers, allowing for location tracking.
Owners are often unaware they have this alarm installed, which complicates the deployment of a firmware update necessary to patch the security vulnerability. The patch has only reached a portion of users due to its distribution through the companion app, which many owners may not have downloaded. UC San Diego researchers disclosed the issue to Acrisure in January 2025, but a fix was not implemented until July 2026, with the company claiming that the real-world risk is low.