Experts warn 2.2 million cars could be hijacked via Bluetooth

Experts warn 2.2 million cars could be hijacked via Bluetooth

One hand on a concealed car door handle
(Image credit: Getty Images)

  • 2.2 million vehicles at risk of Bluetooth attack in California
  • Vulnerability is due to dealer-installed security systems
  • Researchers at the University of California San Diego found that security devices built by Acrisure all rely on the same secure key.

A vulnerability has been found in the KARR and SWDS car security systems manufactured by Acrisure which allows remote control via Bluetooth. The vehicles were equipped with security systems installed by car dealerships in California, including anti-theft and tracking devices. However, thanks to this hack, it appears that vehicles can be unlocked, with additional control given to the attacker.

Researchers at the University of California San Diego found that all 2.2 million automobiles had been purchased from dealerships in Southern California since 2017, although the secondary market means the vehicles could be found elsewhere in the United States, and even as far away as Japan.

Worryingly, researchers also discovered a publicly available database containing information on all vehicles equipped with the security system.

How Bluetooth Controls These Cars

2 million cars with dealer-installed anti-theft systems are at higher risk of theft – YouTube

Look on it

Researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford and Jeep dealerships, and that the affected vehicles had the “KARR-SWDS” label on the driver’s side window, with the anti-theft device mounted under the dashboard.

Operation is simple: a mobile app connects to the KARR security system via Bluetooth and includes functions such as locking and unlocking doors, controlling the horn and flashing the headlights. It can also prevent the car from starting, although this only works if it isn’t already running.

The problem lies in the implementation, which the researchers said relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device would be susceptible to attack.

Changing the secure key is not an option, nor is turning off Bluetooth. What is particularly concerning is that researchers found that even if the buyer does not pay a subscription for the KARR app and system, the hardware is still in place. Worse yet, it has the same access to the vehicle’s doors, ignition, horn and headlights.

Sign up for the TechRadar Pro newsletter to get all the top news, opinions, features and tips your business needs to succeed!

“Removing the devices is not trivial,” Yibo Wei, a doctoral student at UCSD compsci and co-author of the paper, said in the report on the research (which will be fully published in August). “You have to open the dashboard and cut and reconnect the wires that are deeply tied to the computers and the car’s ignition system.”

The patch is available

Jerry Yu, also a co-author, wrote: “Instead of breaking a window to gain access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle and have it unlock the car doors. »

KARR told media that only vehicles installed “with certain Bluetooth-related components” were affected, and the company released a firmware update.


Follow TechRadar on Google News And add us as your favorite source to get our news, reviews and expert opinions in your feeds.


Christian Cawley has extensive experience as a writer and editor in consumer electronics, computing and entertainment media. He has been a contributor to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive and other publications.

He currently leads the team at smart home website Matter Alpha and writes about retro gaming at Gaming Retro.

Exit mobile version