More than 2.2 million vehicles across the US may be exposed to a newly identified security weakness that could allow car thieves to unlock a vehicle remotely and drive off within minutes.
Researchers at the University of California San Diego said the vulnerability can be exploited from as far as 15 feet away. In some cases, an attacker could open the doors to steal the car, while in others they could disable the ignition and leave the owner unable to start the vehicle.
The affected cars were largely sold through Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California from 2017 onward. But because many of those vehicles have since changed hands on the used-car market, potentially vulnerable models may now be on roads throughout the US, Canada and Japan.
The flaw is tied to KARR and SouthWest Dealer Services (SWDS) anti-theft systems that dealerships install beneath the dashboard. These devices are designed to pair with a smartphone app over Bluetooth, giving drivers control over features such as door locks, the horn, headlights and ignition.
According to the researchers, the major security lapse is that every impacted device relies on the same digital key. They compared it to securing millions of products with a password as weak as “1234” while giving owners no option to change it.
After that universal key is pulled from the official app, it can be reused to issue commands to any susceptible vehicle that is close enough to connect via Bluetooth.
Some motorists may have no idea the equipment is installed in their car at all, since dealerships have reportedly left the hardware in place even when customers chose not to pay for the added security service.
Vehicle owners can look for signs such as a KARR or SWDS sticker on the driver-side window, or check underneath the dashboard for a small blinking button that may indicate the system is present.

Scientists at the University of California San Diego found that attackers could target affected vehicles from up to 15 feet away, allowing them to remotely unlock the doors for theft or disable the ignition to leave a driver stranded
The flaw does not allow an attacker to remotely start a vehicle or control one that is already moving.
However, researchers warned that silently unlocking the doors removes one of the largest obstacles facing a car thief.
Once inside, criminals could connect tools ordinarily used by locksmiths to the vehicle and create a working key within minutes. They could then start the engine and drive away.
The system was originally designed to help dealerships manage their inventory and protect cars from theft while they remained on sales lots.
Installed underneath the dashboard on the driver’s side, it connects to a smartphone app through Bluetooth and performs functions similar to a key fob.
Authorized users can lock or unlock the doors, sound the horn, flash the headlights and stop the engine from starting if it is not already running.
Dealerships often market access to the app as a paid security upgrade when a car is sold. But researchers found that the hardware can remain connected and active even when a customer refuses the service.
That means some drivers could be carrying a vulnerable device without knowing it exists.
The team also discovered that public databases contain location information connected to vehicles fitted with the devices.
That data could potentially allow someone to track a specific car, determine where it is regularly parked and then move within Bluetooth range to target it.
UC San Diego researchers began investigating the systems after noticing unfamiliar Bluetooth signals in 2018 while searching for credit card skimmers hidden inside gas pumps.
The signals were eventually traced to devices made by Acrisure and Rockledge, another vehicle security and insurance company.
Researchers said Rockledge devices may have a separate vulnerability, although exploiting it would be more difficult. An attacker would first need to be nearby when a driver used the system, record the digital exchange and replay it later.
The team said it had been unable to confirm those findings with Rockledge because the company had not responded to its disclosure at the time the report was written.
The researchers have withheld technical details that could help criminals reproduce the attack. They also reported the vulnerabilities to the manufacturers, relevant vendors and the National Highway Traffic Safety Administration.
Acrisure has now released a firmware update intended to fix the KARR-SWDS flaw, but it will not automatically be delivered through Honda, Toyota, Mazda, Ford or Jeep.
The system is aftermarket equipment rather than factory-installed technology, meaning affected owners must update it through the KARR app themselves.
‘Many car owners don’t even know that their vehicle is vulnerable,’ said Aaron Schulman, a professor in UC San Diego’s Department of Computer Science and Engineering and one of the study’s senior authors.
‘So we wanted to make sure they were aware by publishing this study.’
Drivers who find a KARR or SWDS label should download or open the official KARR Security app, connect it to the device and install the latest firmware.
Anyone unable to identify or update the system should contact the dealership that sold the car or KARR customer support.
Researchers warned owners not to attempt to rip the hardware out themselves.
‘Removing the devices is not trivial,’ said Yibo Wei, a UC San Diego computer science doctoral student and co-first author of the paper.
‘You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.’
The team argues that future Bluetooth security systems should require someone to physically press a button inside the vehicle before a new smartphone can connect.