Dealer-Installed Alarm Flaw Could Let Hackers Unlock Cars And Kill Engines

Hooded thief tries to break the car's security systems with tablet. Hacking modern car concept
Image Credit: Shutterstock.

Millions of vehicles across the United States may contain dealer-installed security hardware with a vulnerability that researchers say could allow nearby attackers to unlock doors or even disable a vehicle’s ignition. The concerning part is that some owners may not realize the hardware is installed in their cars at all.

The vulnerability affects aftermarket security systems made by Karr Security Systems, whose hardware has reportedly been installed in roughly two million vehicles. The systems are commonly fitted by dealerships, where they can initially be used for inventory management and theft prevention before a vehicle is sold.

According to research from cybersecurity experts at the University of California San Diego, vulnerable Karr hardware could potentially be manipulated by someone within Bluetooth range using specially developed software. Researchers demonstrated attacks that could remotely control certain vehicle functions, including unlocking doors and interfering with the ignition system.

Karr has since developed a firmware update intended to address the vulnerability. Vehicle owners with affected hardware are being encouraged to make sure their systems receive the latest update, even if they never purchased or activated Karr’s subscription-based security services.

The Alarm Might Be Installed Even If You Didn’t Buy It

thief looking at car
Image Credit: Shutterstock.

The unusual aspect of the vulnerability is how Karr’s hardware ends up inside vehicles in the first place. Dealers can install the systems while cars are sitting in inventory, allowing dealership employees to monitor and manage vehicles before they’re sold.

When a customer purchases the car, the dealer may then offer access to the system’s security features as a paid add-on. Customers who decline the service don’t necessarily have the physical hardware removed, meaning some vehicles could leave dealerships with Karr equipment still connected despite the new owner never signing up for the service.

That potentially leaves buyers unaware that an additional Bluetooth-connected device is communicating with their vehicle’s electronics. According to reports on the vulnerability, vehicles equipped with the system may carry window stickers displaying either “Karr” or “SWDS,” although concerned owners can also contact the dealership where their vehicle was purchased.

Researchers Demonstrated Remote Vehicle Control

The UC San Diego researchers found that the vulnerable system could accept unauthorized commands sent over Bluetooth. With the appropriate software and while physically close enough to the vehicle, an attacker could potentially perform actions normally reserved for an authorized user.

Those actions reportedly include unlocking vehicle doors and disabling the ignition. The researchers also found that the system’s Bluetooth connection can remain active for approximately 10 minutes after a vehicle has been switched off, potentially providing another opportunity for an attacker to interact with the hardware.

The vulnerability doesn’t mean anyone with an ordinary smartphone can instantly walk through a parking lot and disable cars. An attacker would need knowledge of the vulnerability, suitable software, and sufficient proximity to an affected vehicle, but researchers have nevertheless characterized the potential consequences as unusually serious for an automotive cybersecurity flaw.

Karr Says The Real-World Risk Is Low

thief breaking into car
Image Credit: Shutterstock.

Karr has pushed back against suggestions that customers face an immediate widespread threat. In a statement reported by Wired, the company described the vulnerability as highly complex and said it presents a low risk under real-world conditions.

The company nevertheless developed a firmware update after being notified about the researchers’ findings. According to the report, the update can be installed through Karr’s smartphone application, including by owners who aren’t currently paying for the company’s subscription services.

Karr also reportedly intends to work with dealerships to notify affected customers. The challenge may be identifying every owner with the hardware, particularly if some buyers weren’t aware that a Karr device remained installed after they purchased their vehicle.

Connected Hardware Creates Another Security Risk

Dealer-installed systems like these highlight a growing cybersecurity challenge as vehicles accumulate additional connected hardware. Even when owners don’t actively use a device or subscribe to its associated services, hardware that remains connected to critical vehicle systems can potentially create another route for attackers.

For affected owners, the immediate priority is ensuring the Karr system has received the latest firmware update. Drivers who suspect their vehicle may contain the hardware can look for Karr or SWDS branding and contact the dealership that sold the car for confirmation.

The episode also raises a broader question for dealerships that install connected security equipment before vehicles are sold. If a customer declines the service, physically removing or fully disabling unnecessary hardware could eliminate a potential security vulnerability rather than leaving an unwanted connected device hidden inside the car.

Author: Andre Nalin

Title: Writer

Andre has worked as a writer and editor for multiple car and motorcycle publications over the last decade, but he has reverted to freelancing these days. He has accumulated a ton of seat time during his ridiculous road trips in highly unsuitable vehicles, and he’s built magazine-featured cars. He prefers it when his bikes and cars are fast and loud, but if he had to pick one, he’d go with loud.

Leave a Comment

Flipboard