Overview
- UC San Diego researchers reported a Bluetooth command-injection vulnerability in Karr alarm modules that can accept remote instructions to unlock doors or disable vehicle ignitions.
- Researchers demonstrated the exploit to reporters and called it extremely serious, with one UCSD professor describing it as among the worst car-hacking threats seen to date.
- Karr’s technology is reported to be installed in roughly 2 million U.S. vehicles and many dealer networks put the hardware on lot cars and sometimes leave it installed after sale, so buyers may not know they have the device.
- Karr has released a firmware patch that can be installed through its companion smartphone app and says it will work with dealers to notify owners, though reporting says it reportedly took about 18 months for the company to issue the fix.
- Key open questions include whether owners know their cars contain Karr hardware, how quickly and completely the app update will be applied, and whether regulators should require removal or explicit buyer consent for dealer-installed tracking and alarm devices.