Particle.news
Download on the App Store

Dealer Bluetooth Units Leave 2.2 Million Cars Vulnerable to Remote Control

A single shared authentication key and a public enrollment database let nearby attackers command locks, lights, horn and engine start while the issued firmware fix is only delivered through a companion app many owners never installed.

Overview

  • University of California San Diego researchers published findings Monday, July 27, 2026, showing dealer‑installed Acrisure KARR/SWDS Bluetooth units can be commanded from about five yards away to unlock doors, flash lights, sound horns and block engine start.
  • The flaw stems from a single shared secure key used across devices and a publicly accessible enrollment database, which together allow one extracted key or crafted command to talk to many units.
  • UCSD traced roughly 2.2 million affected units to vehicles sold through Southern California Honda, Toyota, Mazda, Ford and Jeep dealerships since 2017, and resale means vulnerable cars now circulate beyond California and overseas.
  • Acrisure issued a firmware patch on July 20, 2026, but the update is distributed via the KARR companion app or dealer service, and many owners never installed the app so large numbers likely remain unpatched.
  • Owners should look for KARR/SWDS stickers or a small dashboard button, update the unit via the app or contact their dealer, and regulators and dealers now face scrutiny over disclosure, aftermarket device rules and supply‑chain security.