A device hidden in cars across the US makes it vulnerable to hacking and paralysis. Correct it now


Like modern cars evolved into Multi-ton computers on wheelsdrivers are starting to realize that they need to install security updates for their vehicle codes, just as they would in the case of… phone or Laptop. However, not even the most tech-savvy car owners expect that they’ll need to install a patch for an insecure third-party component that they never installed or ordered — and likely weren’t even aware of — that is plugged into some of their cars’ most sensitive systems, making them vulnerable to surreptitious hacking, tracking, and even roadside paralysis.

That’s the troubling discovery by a team of security researchers at the University of California, San Diego, who found that an aftermarket car alarm model known as the KARR security system, installed in more than 2 million vehicles across the United States by their estimates, could allow any intruder within Bluetooth range to send wireless commands to silently unlock the car at will, turn off the alarm, sound the car’s horn or flash its lights, or even disable its ignition and leave the driver stranded.

KARR alarms are typically installed by car dealers, not manufacturers or owners, and are used as a measure to prevent car theft from car dealers. However, when cars are sold, the alarms are usually not removed, even if the buyer refuses to pay for them as an extra. This means that car owners across the US have a hackable device under their hood and will need to update its code to protect their car, but the device, in many cases, they never purchased and have no idea about.

The KARR security system is connected to the critical systems of more than 2 million vehicles, according to UC San Diego estimates...

The KARR security system is connected to the critical systems of more than 2 million vehicles, according to UC San Diego estimates, all of which need to be patched to protect them from hacking technologies that can track, unlock and paralyze cars.

Photo: Courtesy of David Pilot/UC San Diego

“This is a system that has been added to cars by dealers, and unfortunately it has a severe security vulnerability that would allow anyone to access any of these cars,” says Aaron Shulman, a computer science professor at UCLA who led the research. “It was designed to make cars safer, but ultimately it created a vulnerability that needed to be patched immediately across millions of vehicles. We’re trying to get the word out that you need to scan your car for this device and patch it manually now.”

The company that sells the KARR security system, Acrisure Protection Group, today rolled out a firmware update for the vulnerable Bluetooth model of its aftermarket KARR alarm to fix the security issues uncovered by UC. The UCSD team says car owners who have already installed the KARR Security smartphone app should receive an alert about the firmware update. Those who do not have it installed will need to download the KARR Security System smartphone app (Android, iOS), connect it to their car’s KARR alarm, then click “Customer Service” and “Update Firmware”.

Since at least half of car owners who installed a KARR device did not require it in their cars, according to a UCSD estimate, you can check if your car has the device by looking for a KARR sticker on the driver’s side window of your car — or in some cases reading the sticker, “SWDS” for SouthWest Dealer Services, a subsidiary of Acrisure Protection Group — as well as a small button with a flashing light attached to the underside of your car. Dashboard. Car owners in Southern California are more likely to install the device due to its popularity among auto dealers in the area, but UC San Diego researchers caution that they have found the devices installed in vehicles across the United States and even in other countries.

Leave a Reply

Your email address will not be published. Required fields are marked *