Bluetooth Flaw Lets Hackers Unlock Cars and Kill Engines via Unpaid Alarms

▼ Summary
– Karr sells alarm systems installed in about 2 million U.S. vehicles, but dealers often leave the hardware in cars even if buyers do not pay for the service.
– UC San Diego researchers discovered a Bluetooth vulnerability in Karr’s system that could let attackers unlock doors or disable the ignition.
– Karr issued a firmware update to fix the vulnerability, which can be installed via a smartphone app, but it took 18 months to release the patch.
– The system’s Bluetooth radio stays active for 10 minutes after the car is turned off, widening the window for potential attacks.
– Experts disagree with Karr’s claim that the vulnerability poses low risk, with one professor calling it “probably the worst” car hacking threat to date.
A security flaw in a widely installed aftermarket car alarm system has opened the door for hackers to remotely unlock vehicles, disable engines, and create chaos , all through a simple Bluetooth connection. Researchers at UC San Diego uncovered the vulnerability in systems made by Karr, a company whose technology is embedded in roughly 2 million cars across the United States. The real kicker? Many drivers don’t even know their vehicle has the system, because some dealers install and leave the hardware in place regardless of whether the buyer pays for the service.
The exploit allows attackers to send commands over Bluetooth to a vehicle’s Karr alarm system. Once connected, they can unlock doors, kill the engine, or trigger other disruptive functions. Fortunately, Karr has released a firmware update to patch the issue, which can be applied through a companion smartphone app , and it’s available to anyone, even those who never subscribed to the alarm service. If you’re unsure whether your car is affected, check for stickers reading “Karr” or “SWDS” on the driver-side window. When in doubt, ask your dealer.
Karr downplayed the severity of the flaw, telling Wired that the vulnerability is “highly complex and presents a low risk to customers under real-world conditions.” The company added that it “responded promptly and developed a firmware update to address the issue.” However, the word “promptly” seems generous: it took 18 months for Karr to issue that patch.
UC San Diego researchers disagree with the company’s assessment. One professor called it “probably the worst” car hacking threat discovered to date. The team demonstrated to Wired just how easily an attacker with the right software could compromise a vehicle that hasn’t received the update. Making matters worse, the system’s Bluetooth radio remains active for 10 minutes after the car is turned off, widening the window for potential attacks.
The reason so many cars carry Karr hardware without active subscriptions comes down to dealer practices. More than 3,000 dealerships nationwide work with Karr, often using the systems as a loss prevention tool while vehicles sit on the lot. At the point of sale, customers are offered the chance to pay a recurring fee for continued security. If they decline, the hardware is not automatically removed. Customers may have to specifically request its removal, and dealers don’t always make that easy.
This situation is yet another symptom of the complexities surrounding modern connected car ownership. But unlike other security issues we’ve seen recently , such as the SignalTrace or Flock tracking problems , this one has a straightforward fix. A legal requirement that dealers remove such hardware at the time of sale, unless the customer explicitly consents and pays for ongoing monitoring, would eliminate the risk. Leaving extraneous equipment in vehicles that never needed it in the first place creates an unacceptable vulnerability. Dealers need to understand that every car left with an unused alarm is a potential entry point for bad actors.
(Source: The Drive)




