Technology News

The Hidden Threat: Millions of Cars Vulnerable to Remote Hacking Due to Third-Party Alarm System

Modern vehicles have transformed into sophisticated, connected devices, often described as “computers on wheels.” This evolution necessitates a paradigm shift in vehicle ownership, where drivers must now consider software security updates, akin to those performed on smartphones and laptops, to protect their automobiles from evolving digital threats. However, a recent discovery by security researchers at the University of California San Diego (UCSD) reveals a far more insidious vulnerability: an aftermarket car alarm system, the KARR Security System, has been integrated into the core systems of millions of vehicles without the owners’ knowledge or explicit consent, leaving them susceptible to remote hacking, tracking, and even immobilisation.

This alarming revelation highlights a critical blind spot in automotive cybersecurity, where third-party components, often installed by dealerships, can introduce significant security risks that manufacturers and owners are unaware of. The KARR Security System, estimated to be present in over two million vehicles across the United States, presents a significant cybersecurity challenge due to its inherent design flaws, which allow malicious actors within Bluetooth range to remotely unlock doors, disable alarms, control lights and horns, and, most critically, immobilise the vehicle’s ignition.

The Silent Invasion: Unveiling the KARR Vulnerability

The KARR Security System is typically installed by car dealerships as an anti-theft measure for their inventory. The concerning practice, as uncovered by the UCSD research team, is that these alarm systems are often not removed when a vehicle is sold, even if the buyer declines to purchase it as an additional feature. This means that a vast number of car owners across the US are unknowingly operating vehicles equipped with a device that requires immediate security patching, a device they never selected or even knew existed.

Professor Aaron Schulman, the lead computer science professor at UCSD overseeing the research, described the situation as deeply troubling. "This is a system added to cars by dealers, and unfortunately, it has a severe vulnerability that allows anyone to gain access to any of these cars," Schulman stated. "It’s designed to make cars more secure, but ultimately, it has created a vulnerability that needs to be patched immediately across millions of vehicles. We’re trying to get the word out that you need to check your car for this device and manually patch it now."

The implications of such a widespread and undetected vulnerability are profound. It bypasses traditional vehicle security measures and leaves drivers exposed to a range of malicious activities. The potential for carjacking is significantly elevated, as a hacker could silently unlock a vehicle at a traffic light. Furthermore, the ability to immobilise a vehicle remotely could be used for targeted harassment, extortion, or even as a precursor to more serious crimes.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

A Timeline of Discovery and Response

The journey to uncovering this critical flaw began subtly. In 2018, UCSD researcher Nishant Bhaskar was analysing radio-enabled "skimmer" devices used to steal credit card information at gas stations. During his investigation, he began detecting unusual Bluetooth signals emanating from vehicles at these locations. Further analysis revealed that these signals were consistent across a wide range of car makes and models on highways, leading him to investigate the source. His research identified the signals as originating from the KARR alarm device by cross-referencing them with Federal Communications Commission (FCC) databases.

Years later, in 2024, during a search for a summer research project, then-graduate researcher Jerry Yu was tasked by Professor Schulman to investigate the security of the KARR device. Yu’s investigation quickly yielded a significant breakthrough: he identified a universal authentication key embedded within the KARR smartphone application, which is used by customers who have paid for the alarm system. This key, when present in the app’s code, allowed for the replication of radio commands that any nearby Bluetooth-enabled KARR device would accept.

"Once we reverse-engineered their application, we quickly realized after understanding their internal authentication protocol that it was so simple that we could extract it and re-implement it as our own application, which we did," Yu explained. This custom-built application demonstrated the ability to unlock "every single car they’ve ever put this in."

The UCSD team’s findings were shared with Acrisure Protection Group, the company that sells the KARR Security System, in January of the previous year. However, it took nearly 18 months for the company to release a firmware update addressing the critical vulnerabilities. The patch was rolled out only weeks before UCSD’s scheduled presentations of their findings at prominent cybersecurity conferences, including the Defcon hacker conference and the Usenix security conference.

The Scope of the Threat: Millions of Vehicles at Risk

To ascertain the scale of the KARR device’s deployment, UCSD researcher Yibo Wei utilised the open-source radio information database WiGLE. This crowdsourced platform collects radio signal data from contributors worldwide. By analysing WiGLE scans and extrapolating from device serial numbers, Wei estimated that over two million Bluetooth-enabled KARR devices have been installed in vehicles across the United States.

The research team’s findings suggest a particularly high concentration of these devices in Southern California, attributed to their widespread adoption by car dealers in the region. However, the researchers caution that these vulnerable KARR-enabled vehicles have been identified across the entire US and even in other countries, underscoring the global nature of this cybersecurity threat.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

The WiGLE data not only provides an estimate of affected vehicles but also offers a potential tool for malicious actors. The historical location data of vehicles identified by their KARR device’s Bluetooth signature could be used to track their movements and identify frequent parking spots, creating an easy scouting mechanism for potential theft or sabotage.

During a demonstration for WIRED, the UCSD researchers showcased the ease with which their custom app could interact with KARR-enabled vehicles. In a test drive around the UCSD campus, their app detected 97 vehicles with beaconing KARR devices in just 20 minutes, illustrating the pervasive nature of the vulnerability.

Demonstrating the Danger: Beyond Simple Unlocking

The KARR Security System’s vulnerabilities extend beyond merely unlocking car doors. The UCSD research team’s demonstrations revealed a chilling array of potential exploits:

  • Remote Unlocking and Carjacking: The app could unlock a vehicle’s doors with a simple tap, facilitating opportunistic theft or carjacking.
  • Vehicle Immobilisation: Attackers could remotely disable a parked car’s ignition, leaving drivers stranded.
  • Disruption and Harassment ("Mayhem Mode"): A specially designed "mayhem" button within the app could trigger multiple cars in proximity to simultaneously and repeatedly honk their horns and flash their lights, creating chaos and potentially distracting drivers.
  • Stealthy Entry for Theft: While the KARR vulnerability doesn’t allow direct ignition start, it can be combined with readily available locksmith tools. Once inside a vehicle via the compromised KARR system, thieves can use these tools to create a working key within minutes, enabling them to drive the car away. This combination bypasses the need for forceful entry methods that would typically trigger alarms.

While the KARR device’s vulnerabilities do not allow a hacker to directly start the car’s engine, the ability to gain silent access to the vehicle significantly lowers the barrier for traditional car theft methods that require physical entry.

The Company’s Response and Criticisms

In response to WIRED’s inquiries, a spokesperson for Acrisure Protection Group issued a statement acknowledging the vulnerability. "The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions. Nevertheless, we responded promptly and developed a firmware update to address the issue."

The company stated its intention to notify car owners about the patch through the KARR Security app, its website, and dealer communications. However, Acrisure did not elaborate on its strategy for reaching car owners who are unaware of the device’s presence in their vehicles, particularly those who may have purchased used cars where the original dealerships can no longer be contacted.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

The UCSD researchers expressed skepticism regarding Acrisure’s claims of a "low risk" and "prompt" response. They highlighted that the 18-month delay in releasing the patch, coupled with the inherent nature of the vulnerability, paints a different picture.

Professor Stefan Savage, another UCSD computer science professor who was not involved in the KARR research but has a history of hacking vehicle systems, described the KARR flaw as "probably the worst" car hacking threat discovered to date. "It affects a large number of vehicles, the manufacturer of your car can’t fix it, and you don’t even know you have the problem," Savage commented. "It provides all the elements a car thief would want, but you have none of the advantages we normally have in terms of defending it, because you’re disconnected from the supply chain that put it there."

The Hidden Activation and Subtle Warnings

A crucial aspect of the KARR vulnerability is its persistence even in "deactivated" states. For car owners who did not purchase the KARR alarm as an add-on, the device remains in the vehicle and continues to broadcast and receive Bluetooth signals. This state persists for up to 10 minutes after the car is turned off. The UCSD researchers discovered that they could activate these "deactivated" KARR devices with a simple radio command, immediately enabling their suite of hacking capabilities.

When a KARR device is activated from this dormant state, it emits a brief beep from the car’s horn and a flicker of its lights. This serves as the only potential warning for owners of unpurchased KARR systems that their vehicle has been put into a hackable state. For the hundreds of thousands of KARR customers who did pay for the alarm system, this subtle warning is absent, meaning any hacking attempt would go entirely unnoticed.

The Core of the Insecurity: A Shared Authentication Key

The fundamental flaw that underpins all these hacking possibilities is the use of a single, shared authentication key across all KARR devices. This key was not only found within the KARR smartphone app but also within the device’s code itself. By reverse-engineering the KARR app’s code, the UCSD team was able to reconstruct this key and develop their own application that could successfully spoof radio commands, making them appear legitimate to any nearby Bluetooth-enabled KARR device.

This shared key architecture is a critical design oversight. In secure systems, each device or user typically has unique credentials, or at the very least, a robust mechanism for key exchange and management. The universal nature of the KARR key means that a compromise of one device or the app effectively compromises all others.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now

The Broader Implications for Automotive Cybersecurity

The KARR Security System incident underscores a growing concern within the automotive industry: the security implications of third-party integrations. As vehicles become more complex, relying on a wider array of electronic control units (ECUs) and software modules, the potential for vulnerabilities introduced by aftermarket components or even by suppliers within the automotive supply chain increases exponentially.

This case highlights several critical issues:

  • Lack of Transparency: Car owners are often unaware of the full spectrum of software and hardware components operating within their vehicles, especially those not directly installed by the manufacturer.
  • Dealer-Installed Risks: The reliance on dealerships for installing additional security features, without adequate oversight or security vetting, creates a significant risk.
  • Patching Challenges: When a vulnerability lies within a third-party component, the vehicle manufacturer is often unable to issue a direct fix, placing the burden on the owner or the third-party provider.
  • Supply Chain Security: The KARR incident raises questions about the security practices of component suppliers and the due diligence performed by both dealerships and vehicle manufacturers in vetting these third-party integrations.

The UCSD researchers’ findings serve as a stark warning. Professor Schulman emphasised the need for widespread public awareness and proactive action. "When you install something by default at a dealer in every car that’s sold, the pervasiveness of that vulnerability is going to be unimaginable," he said. "This is why we need to publicize this and get it out there, because the only way this will eventually get solved is if we get everyone on board and to fix it themselves."

For car owners, the immediate imperative is to check for the presence of a KARR device. This can be done by looking for a KARR sticker on the driver-side window, or sometimes a sticker reading "SWDS" (SouthWest Dealer Services, a subsidiary of Acrisure Protection Group). Additionally, a small button with a blinking light may be found attached to the underside of the dashboard.

If a KARR device is identified, owners should download the KARR Security System smartphone app (available on both Android and iOS), connect it to their vehicle’s alarm, and navigate to "customer service" followed by "firmware update." For those who did not purchase the alarm, vigilance regarding the brief horn beep and light flicker when activating the car may provide a clue.

The KARR Security System incident is a critical reminder that in the age of connected vehicles, cybersecurity is not merely a feature but a fundamental necessity, demanding continuous attention from manufacturers, suppliers, dealerships, and, crucially, the drivers themselves. The long-term implications for automotive security and consumer trust hinge on addressing such vulnerabilities with the urgency and transparency they demand.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Blog News Tweets
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.