Bluetooth flaw in KARR and SWDS dealer-installed car security systems can unlock or disable millions of vehicles

Researchers say at least 2.2 million vehicles with KARR and SWDS aftermarket security systems can be attacked over Bluetooth from nearby, allowing doors to be unlocked or a stopped car to be prevented from starting. UC San Diego found the Acrisure-made devices relied on the same cryptographic key across units, enabling unauthorized Bluetooth access within about five yards. Affected vehicles were reportedly sold through thousands of dealerships, especially Southern California Honda, Toyota, Mazda, Ford, and Jeep dealers, and KARR says firmware updates are available.
Why it matters: Car owners may be at risk even if they declined the dealer security service, because the hardware can remain installed and active. Anyone with an affected vehicle should check for KARR or SWDS equipment and apply the vendor's firmware update as soon as possible.

Sources

In Other News: Dolphin X AI-Powered Malware, Car Anti-Theft Device Hack, 400 Linux Kernel Flaws
SecurityWeek News 2026.07.24 75% relevant
The headline reference to a car anti-theft device hack points to the same vehicle security issue, though the body text excerpt does not add substantive new details beyond highlighting it as part of the week’s notable stories.
Millions of California-bought cars can be hijacked via Bluetooth
2026.07.23 100% relevant
This article appears to be the first widely reported disclosure of the UC San Diego findings about a shared Bluetooth key flaw in KARR and SWDS vehicle security devices and the resulting patch guidance.
← Back to all stories