KARR Bluetooth vulnerability puts 2.2 million car security systems at risk
UC San Diego researchers say KARR and SWDS dealer security devices can be attacked over Bluetooth; KARR says a firmware update is available.
By Dominic Okoye · Staff Writer
· 3 min read
The KARR Bluetooth vulnerability described by University of California San Diego researchers affects at least 2.2 million vehicles with dealer-installed KARR and SWDS security systems, the university said. The issue matters beyond one aftermarket product line because the devices are installed through car dealers and can remain active even when a buyer did not pay for the service.
UCSD said researchers found that KARR and SWDS devices made by Acrisure rely on a shared secure key. With that key, a Bluetooth-capable device and physical proximity of about five yards, an attacker could connect to the unit in a vehicle and unlock doors, trigger the horn, flash the headlights or stop a parked vehicle from starting, according to the researchers.
Jerry Yu, a UCSD computer science graduate and co-author of the research, said in the university’s announcement that a thief would not need to break a window to enter a vehicle if they could connect to the device over Bluetooth and command it to unlock the doors.
What is the KARR Bluetooth vulnerability?
KARR and SWDS units are dealership-installed security and tracking devices that add remote-control features similar to a key fob and can help locate a car after theft, according to UCSD. The vulnerability, as described by the researchers, is a Bluetooth attack enabled by a shared key across the affected devices.
UCSD said the systems are commonly sold as paid dealer upgrades in the United States. KARR says its products are offered through more than 3,000 dealerships nationwide.
The dealer-install model creates an exposure problem for owners. According to the researchers, the devices can stay powered and reachable even if the car buyer declines the KARR or SWDS service contract. UCSD computer science PhD candidate Yibo Wei, another co-author, said removal is difficult because it requires opening the dashboard and cutting and reconnecting wiring tied into vehicle computers and the ignition system.
The researchers said most of the vulnerable vehicles were bought in Southern California over the past nine years from Honda, Toyota, Mazda, Ford and Jeep dealerships. Used-car sales mean the affected vehicles are not limited to California; the team said they can now be found across the United States and as far away as Japan. UCSD also said the researchers found a public database containing information about vehicles equipped with the devices.
What has KARR said about the issue?
KARR Security has released a firmware update for affected devices, and UCSD said the update can be installed by both active customers and owners whose security systems are inactive. Instructions are available on the company’s website.
KARR disputed the breadth of the UCSD finding. A company spokesperson said only a small percentage of devices with certain Bluetooth-related components are affected, and described the vulnerability as complex and low risk under real-world conditions. The company also said it developed a firmware update to address the issue. KARR did not directly say whether it is notifying customers who need to install the update.
The research began years ago during UCSD work on credit card skimmers, when the team noticed unfamiliar Bluetooth fingerprints and traced them to vehicle security systems. The researchers are scheduled to present the work at DEF CON on August 9 and at the USENIX Security conference on August 12, when the full writeup is expected.
This story draws on original reporting from The Register.