
RESEARCHERS at the University of California San Diego have found a security flaw in dealer‑installed KARR and SWDS anti‑theft systems that affects roughly 2.2 million vehicles, primarily sold through dealerships in Southern California according to a campus advisory.
The vulnerability stems from a static authentication key that is identical across all affected units and is stored in plain text within the KARR mobile application as reported by a security news site. An attacker equipped with a standard Bluetooth transceiver within about five metres can transmit unlock commands, activate the horn, flash the headlights or prevent the engine from starting. No CVE identifier has been assigned to the issue at this time.
In addition, the alarms continuously broadcast their Bluetooth MAC addresses, which can be harvested for passive location tracking of the vehicle researchers noted. Many owners are unaware that the alarm was fitted at the point of sale, complicating efforts to push out a remedial firmware update. Because the same key is used everywhere, knowledge of it allows anyone within range to replicate the legitimate signal.
The University of California San Diego team disclosed the findings privately to the vendor and will present the full technical analysis at a conference on 12 August. To date there is no public evidence that the flaw has been exploited in the wild, but the low barrier to entry means it could be weaponised quickly if the details become widely known.
Owners should first check their purchase paperwork or look for a label indicating a KARR or SWDS alarm to confirm whether their vehicle is affected. If the system is present, they need to download the official companion app from the manufacturer’s website and apply any firmware update that replaces the shared key with a unique, per‑device value. The update is intended to generate a distinct secret for each unit, removing the universal secret that enables the attack.
When the app is not installed, contacting the selling dealer to request the update or temporarily disabling the alarm’s Bluetooth functionality can reduce risk while a patch is arranged. Keeping the vehicle’s Bluetooth discoverable mode turned off when the car is parked also limits the window of opportunity for an attacker. Regularly reviewing the alarm’s documentation helps ensure that any future security notices are not missed.