Sponsored

KARR security system issue

Auer

Well-Known Member
Joined
Jun 23, 2026
Threads
2
Messages
90
Reaction score
142
Location
North East
Vehicles
Shoes
Not a Slate thing but here it is:
https://www.devdigest.org/articles/2m-cars-hackable-via-hidden-karr-alarm-patch-now

Over 2 Million Cars Have a Hidden, Hackable Alarm
A team of security researchers at UC San Diego has uncovered a severe vulnerability in the KARR Security System, an aftermarket car alarm installed in more than 2 million vehicles across the US. The flaw allows any attacker within Bluetooth range to unlock the car, disable the ignition, or trigger the horn and lights—all without any physical access. The device is typically installed by car dealers without the buyer's knowledge, and remains in the vehicle even if the buyer declines to pay for it.

The Flaw: A Single Shared Authentication Key
The root cause is a single authentication key shared across all KARR devices. The researchers found this key hardcoded in the KARR smartphone app. By reverse-engineering the app, they created a proof-of-concept Android app that spoofs radio commands accepted by any nearby KARR device.

> "Once we reverse-engineered their application, we quickly realized after understanding their internal authentication protocol that it was so simple that we could extract it and re-implement it as our own application," said Jerry Yu, the graduate researcher who led the analysis.

The key allows the attacker to send commands to unlock doors, disable the ignition (preventing the car from starting), and trigger the horn or lights. The device remains beaconing and accepting Bluetooth signals for up to 10 minutes after the car is turned off, expanding the attack window.

Impact: Theft, Tracking, and Mayhem
The researchers demonstrated multiple attack scenarios:
  • Silent Unlock: Unlock a car at a stoplight to enable theft or carjacking.
  • Ignition Disable: Paralyze a parked car so it won't start.
  • "Mayhem" Mode: Hack multiple cars to simultaneously honk and flash lights.
While the vulnerability doesn't allow starting the engine, the researchers showed that once inside, a thief can use a locksmith tool (available online) to create a working key in minutes. The KARR flaw removes the need to break a window or trigger an alarm, making the theft much easier.
Additionally, the Bluetooth beacon from the KARR device can be used to track a car's location over time. The researchers used the open-source WiGLE database to estimate the number of affected vehicles and found that they could locate vulnerable cars virtually anywhere.

Also at Wired:
https://www.wired.com/story/a-devic...rable-to-hacking-and-paralysis-patch-it-now/?
 
Last edited:

Freyar

Well-Known Member
Joined
Jul 17, 2026
Threads
0
Messages
64
Reaction score
99
Location
Utah
Vehicles
2013 Mini Cooper S
Forwarded on to family members that have gotten cars more recently from local dealerships. What a pain.
 

KevinRS

Well-Known Member
First Name
Kevin
Joined
Jul 4, 2025
Threads
7
Messages
1,797
Reaction score
2,214
Location
California
Vehicles
Nissan Versa
Ok, my car has that KARR sticker, seeing this I attempted to update, but apparently mine does not have the bluetooth system, so it doesn't apply.
 
 





Top