Monday, July 27, 2026
No Result
View All Result
LJ News Opinions
  • Home
  • U.S.
  • Politics
  • World News
  • Business
  • Entertainment
  • Sports
  • Technology
  • Health
  • Opinions
  • Home
  • U.S.
  • Politics
  • World News
  • Business
  • Entertainment
  • Sports
  • Technology
  • Health
  • Opinions
No Result
View All Result
LJ News Opinions
No Result
View All Result
Home Technology

Millions told to check cars NOW over flaw that lets thieves steal vehicles in minutes

by LJ News Opinions
July 27, 2026
in Technology
0
Share on FacebookShare on Twitter


At least 2.2 million cars in the US are at risk of a newly found flaw that lets thieves remotely unlock vehicles and drive away in minutes.

Scientists at the University of California San Diego found that attackers could target affected vehicles from up to 15 feet away, allowing them to remotely unlock the doors for theft or disable the ignition to leave a driver stranded.

Most were originally sold by Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and today. However, used-car sales mean potentially vulnerable vehicles are now scattered across the US, Canada and even Japan.

The problem lies in KARR and SouthWest Dealer Services (SWDS) anti-theft devices installed under the dashboard by dealerships. Drivers can use a smartphone app to connect to the device through Bluetooth and control the locks, horn, headlights and ignition.

Researchers discovered that every affected device uses the same digital security key. It is similar to protecting millions of devices with the password ‘1234’ while preventing owners from changing it.

Once that shared key is extracted from the official app, it can be used to send commands to any vulnerable vehicle within Bluetooth range.

Many drivers may not realize the hardware is inside their car because dealerships sometimes leave it installed even when buyers decline the paid security service. 

Owners can check for a KARR or SWDS sticker on the driver-side window or a small blinking button beneath the dashboard.

Scientists at the University of California San Diego found that attackers could target affected vehicles from up to 15 feet away, allowing them to remotely unlock the doors for theft or disable the ignition to leave a driver stranded

The flaw does not allow an attacker to remotely start a vehicle or control one that is already moving.

However, researchers warned that silently unlocking the doors removes one of the largest obstacles facing a car thief.

Once inside, criminals could connect tools ordinarily used by locksmiths to the vehicle and create a working key within minutes. They could then start the engine and drive away.

The system was originally designed to help dealerships manage their inventory and protect cars from theft while they remained on sales lots.

Installed underneath the dashboard on the driver’s side, it connects to a smartphone app through Bluetooth and performs functions similar to a key fob.

Authorized users can lock or unlock the doors, sound the horn, flash the headlights and stop the engine from starting if it is not already running.

Dealerships often market access to the app as a paid security upgrade when a car is sold. But researchers found that the hardware can remain connected and active even when a customer refuses the service.

That means some drivers could be carrying a vulnerable device without knowing it exists.

The team also discovered that public databases contain location information connected to vehicles fitted with the devices.

That data could potentially allow someone to track a specific car, determine where it is regularly parked and then move within Bluetooth range to target it.

UC San Diego researchers began investigating the systems after noticing unfamiliar Bluetooth signals in 2018 while searching for credit card skimmers hidden inside gas pumps.

The signals were eventually traced to devices made by Acrisure and Rockledge, another vehicle security and insurance company.

Researchers said Rockledge devices may have a separate vulnerability, although exploiting it would be more difficult. An attacker would first need to be nearby when a driver used the system, record the digital exchange and replay it later.

The team said it had been unable to confirm those findings with Rockledge because the company had not responded to its disclosure at the time the report was written.

The researchers have withheld technical details that could help criminals reproduce the attack. They also reported the vulnerabilities to the manufacturers, relevant vendors and the National Highway Traffic Safety Administration.

Acrisure has now released a firmware update intended to fix the KARR-SWDS flaw, but it will not automatically be delivered through Honda, Toyota, Mazda, Ford or Jeep.

The system is aftermarket equipment rather than factory-installed technology, meaning affected owners must update it through the KARR app themselves.

‘Many car owners don’t even know that their vehicle is vulnerable,’ said Aaron Schulman, a professor in UC San Diego’s Department of Computer Science and Engineering and one of the study’s senior authors.

‘So we wanted to make sure they were aware by publishing this study.’

Drivers who find a KARR or SWDS label should download or open the official KARR Security app, connect it to the device and install the latest firmware.

Anyone unable to identify or update the system should contact the dealership that sold the car or KARR customer support.

Researchers warned owners not to attempt to rip the hardware out themselves.

‘Removing the devices is not trivial,’ said Yibo Wei, a UC San Diego computer science doctoral student and co-first author of the paper.

‘You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.’

The team argues that future Bluetooth security systems should require someone to physically press a button inside the vehicle before a new smartphone can connect.

Source link

Tags: CanadadailymailJapansciencetech
LJ News Opinions

LJ News Opinions

Next Post

Fauci diary entries: 'Press is going wild with me'

Recommended

Drone attack on Israel puts spotlight on Iron Dome’s limitations

2 years ago

Winter weather: Snow could impact several major cities along I-95 corridor

6 months ago

Popular News

    Connect with us

    LJ News Opinions

    Welcome to LJ News Opinions, where breaking news stories have captivated us for over 20 years.
    Join us in this journey of sharing points of view about the news – read, react, engage, and unleash your opinion!

    Category

    • Business
    • Entertainment
    • Health
    • Opinions
    • Politics
    • Sports
    • Technology
    • U.S.
    • World News

    Site links

    • Home
    • About us
    • Contact

    Legal Pages

    • Privacy Policy
    • Cookie Privacy Policy
    • Terms of Use
    • Disclaimer
    • California Consumer Privacy Act (CCPA)
    • DMCA
    • About us
    • Advertise
    • Contact

    © 2024, All rights reserved.

    No Result
    View All Result
    • Home
    • U.S.
    • Politics
    • World News
    • Business
    • Entertainment
    • Sports
    • Technology
    • Health
    • Opinions

    © 2024, All rights reserved.