San Diego Car Alarms Hacked: Dealer Add-Ons Put 2 Million Rides At Risk

Millions of cars, many of them rolling off Southern California lots, may have an anti-theft system that hackers can flip into a remote-control toy. University of California San Diego researchers say a dealer-installed Bluetooth gadget wired into vehicles can be hijacked nearby to unlock doors, trigger alarms or even keep a parked car from starting.

The team estimates at least 2.2 million KARR/SWDS units are in circulation, and the product’s operator has pushed out a firmware update that owners must install themselves through a smartphone app. The finding has led to urgent warnings for drivers, particularly in the San Diego region, where dealerships frequently added the devices to cars before sale.

Researchers find a single shared key undercuts security

UC San Diego computer scientists say they reverse‑engineered the KARR Security System and discovered that Bluetooth‑enabled units rely on one hardcoded authentication key shared across devices. Once they extracted that key, they found they could spoof the radio commands the alarm accepts, unlocking doors, disarming alarms, honking horns and blocking engine starts when the vehicle is off.

The researchers used crowdsourced radio‑signal databases and device serial numbers to estimate how widely the hardware is deployed and disclosed their findings to federal regulators, according to UC San Diego.

Proof-of-concept demos show how an attacker could act

In published demos, the UCSD team showed how little sophistication an attacker might need. Using a homemade Android app to impersonate the official KARR client, they sent spoofed commands to nearby units, remotely unlocking cars, setting off synchronized horn-and-light chaos and leaving parked vehicles unable to start…

Story continues

TRENDING NOW

LATEST LOCAL NEWS