A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Researchers found a dealer-installed KARR alarm in millions of cars can be hacked over Bluetooth to unlock, track, or disable vehicles until owners patch it.
Intelligence analysis by GPT-5.4 Mini

UC San Diego researchers say a widely installed aftermarket KARR alarm, often left in cars without owners realizing it, can be attacked from Bluetooth range. The flaw can silently unlock vehicles, trigger alerts, or disable ignition, and the vendor has now issued a firmware fix.
A hidden gadget was put into many cars by dealers, like a secret lock box in the trunk. Researchers found it could be opened from nearby with a phone, so the company had to release a fix.
Analysis
Hidden Hardware, Hidden Risk
This story is unnerving because the vulnerable component is not some optional gadget drivers installed themselves. According to WIRED, dealers often add the KARR alarm to protect lot inventory, then the device stays in the vehicle after sale even when the buyer never asked for it. That creates a security problem with no obvious owner, no clear support path, and no easy way for the car maker to help.
The broader lesson is that modern cars inherit supply-chain risk in the same way laptops inherit preinstalled software risk, except with much higher stakes. A hidden device wired into critical systems can become a permanent weakness long after the original purpose has expired. That makes disclosure and patching harder than a normal app update, because the people who need the fix may not even know the component exists.
A Bluetooth Bug With Real Control
The researchers' claims are unusually practical, not theoretical. WIRED reports that the flaw can let someone within Bluetooth range unlock the car, silence the alarm, honk the horn, flash the lights, or even disable ignition. In other words, the attack is not just about surveillance. It can interfere with basic control of the vehicle.
That matters because car security failures become more serious when they cross from data exposure into physical disruption. The article frames the issue as a threat to stealthy hacking, tracking, and roadside paralysis, which raises the stakes beyond ordinary nuisance vulnerabilities. A bug that can strand a driver or make theft easier is a direct safety and trust problem.
Why The Patch Problem Is The Real Story
Acrisure Protection Group says it has now released a firmware update for the vulnerable Bluetooth model, and the article says owners can get it through the KARR app or by downloading the app and navigating to the firmware update option. That is the good news. But the fix path still depends on people recognizing that they have the device, finding the right app, and completing a manual update.
That is where the distribution problem becomes part of the security story. WIRED notes that at least half of the affected owners may not have knowingly opted into the system, and some cars may have changed hands since installation. A vulnerability with a patch is still dangerous when the patch cannot reliably reach the people exposed to it, especially when the device was added outside the normal manufacturer relationship.
Key points
- UC San Diego researchers say a dealer-installed KARR alarm in more than 2 million vehicles has a serious Bluetooth vulnerability.
- The flaw can let an attacker unlock cars, disable alarms, trigger the horn or lights, and even disable ignition.
- Acrisure Protection Group says it has released a firmware update for the vulnerable model.
- Many owners may not know the device is installed because dealers often leave it in the car after sale.
- The article says the patching problem is hard because affected drivers may not know they need to update anything.
If owners find the device and install the firmware update, the flaw can be closed before it is abused at scale. The alert through the app, website, and dealer channels could also help more drivers discover a device they never knew was there.
Many owners may never learn that the KARR device is installed in their cars, so the patch may miss the people who need it most. The long delay before a fix also suggests attackers had time to study the weakness, and the Bluetooth attack path could still be useful wherever the update is not applied.



