Millions of vehicles across the United States may contain dealer-installed security hardware with a vulnerability that researchers say could allow nearby attackers to unlock doors or even disable a vehicle’s ignition. The concerning part is that some owners may not realize the hardware is installed in their cars at all.
The vulnerability affects aftermarket security systems made by Karr Security Systems, whose hardware has reportedly been installed in roughly two million vehicles. The systems are commonly fitted by dealerships, where they can initially be used for inventory management and theft prevention before a vehicle is sold.
According to research from cybersecurity experts at the University of California San Diego, vulnerable Karr hardware could potentially be manipulated by someone within Bluetooth range using specially developed software. Researchers demonstrated attacks that could remotely control certain vehicle functions, including unlocking doors and interfering with the ignition system.
Karr has since developed a firmware update intended to address the vulnerability. Vehicle owners with affected hardware are being encouraged to make sure their systems receive the latest update, even if they never purchased or activated Karr’s subscription-based security services.
The Alarm Might Be Installed Even If You Didn’t Buy It

The unusual aspect of the vulnerability is how Karr’s hardware ends up inside vehicles in the first place. Dealers can install the systems while cars are sitting in inventory, allowing dealership employees to monitor and manage vehicles before they’re sold.
When a customer purchases the car, the dealer may then offer access to the system’s security features as a paid add-on. Customers who decline the service don’t necessarily have the physical hardware removed, meaning some vehicles could leave dealerships with Karr equipment still connected despite the new owner never signing up for the service.
That potentially leaves buyers unaware that an additional Bluetooth-connected device is communicating with their vehicle’s electronics. According to reports on the vulnerability, vehicles equipped with the system may carry window stickers displaying either “Karr” or “SWDS,” although concerned owners can also contact the dealership where their vehicle was purchased.
Researchers Demonstrated Remote Vehicle Control
The UC San Diego researchers found that the vulnerable system could accept unauthorized commands sent over Bluetooth. With the appropriate software and while physically close enough to the vehicle, an attacker could potentially perform actions normally reserved for an authorized user.
Those actions reportedly include unlocking vehicle doors and disabling the ignition. The researchers also found that the system’s Bluetooth connection can remain active for approximately 10 minutes after a vehicle has been switched off, potentially providing another opportunity for an attacker to interact with the hardware.
The vulnerability doesn’t mean anyone with an ordinary smartphone can instantly walk through a parking lot and disable cars. An attacker would need knowledge of the vulnerability, suitable software, and sufficient proximity to an affected vehicle, but researchers have nevertheless characterized the potential consequences as unusually serious for an automotive cybersecurity flaw.
Karr Says The Real-World Risk Is Low

Karr has pushed back against suggestions that customers face an immediate widespread threat. In a statement reported by Wired, the company described the vulnerability as highly complex and said it presents a low risk under real-world conditions.
The company nevertheless developed a firmware update after being notified about the researchers’ findings. According to the report, the update can be installed through Karr’s smartphone application, including by owners who aren’t currently paying for the company’s subscription services.
Karr also reportedly intends to work with dealerships to notify affected customers. The challenge may be identifying every owner with the hardware, particularly if some buyers weren’t aware that a Karr device remained installed after they purchased their vehicle.
Connected Hardware Creates Another Security Risk
Dealer-installed systems like these highlight a growing cybersecurity challenge as vehicles accumulate additional connected hardware. Even when owners don’t actively use a device or subscribe to its associated services, hardware that remains connected to critical vehicle systems can potentially create another route for attackers.
For affected owners, the immediate priority is ensuring the Karr system has received the latest firmware update. Drivers who suspect their vehicle may contain the hardware can look for Karr or SWDS branding and contact the dealership that sold the car for confirmation.
The episode also raises a broader question for dealerships that install connected security equipment before vehicles are sold. If a customer declines the service, physically removing or fully disabling unnecessary hardware could eliminate a potential security vulnerability rather than leaving an unwanted connected device hidden inside the car.
