Computer scientists at the University of California, San Diego, uncovered a higher risk of theft in cars with dealer-installed anti-theft systems in Southern California since 2017.
More than 2 million cars could be vulnerable to an attack that allows thieves to lock and unlock doors from as far as five yards away and immobilize vehicle engines remotely via a Bluetooth connection, according to a press release issued last week by the university.
The device, which is controlled via a smartphone app, is installed underneath the dashboard on the driver’s side and connects the vehicle and app via Bluetooth, scientists said.
The app acts much like a key fob: it can lock and unlock doors, honk the horn, and flash headlights as a warning. In addition, the device can prevent the car from starting as long as the car isn’t already running.
The researchers found that all KARR-SWDS devices rely on the same secure key. Once the key was cracked, they had access to all the cars equipped with these devices.
Even if the buyer declines the upgrade, the device remains active, leaving the vehicle vulnerable to an attacker in certain situations, researchers said.
Vehicles purchased at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to present, with a sticker displaying the word “KARR” or “SWDS” on the driver’s-side window, are at risk.
“Many car owners don’t even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study,” said Aaron Schulman, a professor in the UC San Diego Department of Computer Science and Engineering, and one of the study’s senior authors.
Acrisure, the company selling these devices, released a patch to fix the vulnerability on July 20, 2026, requiring downloading an app.
“Removing the devices is not trivial. You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system,” said Yibo Wei, who is also a computer science Ph.D. student in Schulman’s group at UC San Diego and the paper’s co-first author.
The researchers, led by Schulman, will detail how they discovered the vulnerability and reverse-engineered it at the DEF CON conference Aug. 9 in Las Vegas and the USENIX Security conference Aug. 12 in Baltimore.
The research was supported in part by a grant from the National Science Foundation (grant no. CNS-2239163).
BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems
Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Nishant Bhaskar and Aaron Schulman, Department of Computer Science and Engineering, University of California San Diego, UC San Diego, Christian Dameff, UC San Diego Health
https://today.ucsd.edu/story/2-million-cars-with-anti-theft-systems-installed-by-dealers-are-at-higher-risk-of-theft


New York Approves 22% Workers’ Compensation Cost Reduction
Deep Dive: Understanding Data Center Perils
Mapfre to Acquire Safety Insurance in $1.5B in Cash Deal
Waymo Driverless Cars Crash Less Than Human Drivers: IIHS Study