At least 2.2 million cars in the United States are vulnerable to a newly discovered flaw that lets thieves remotely unlock vehicles and drive away within minutes, according to researchers at the University of California San Diego.
The scientists found that attackers could target affected vehicles from up to 15 feet away, remotely unlocking doors for theft or disabling the ignition to strand a driver.
Most of the vehicles were originally sold by Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California between 2017 and today. Because of used-car sales, potentially vulnerable vehicles are now scattered across the United States, Canada and Japan.
The issue lies in KARR and SouthWest Dealer Services, or SWDS, anti-theft devices installed under the dashboard by dealerships. Drivers can use a smartphone app to connect to the device through Bluetooth and control the locks, horn, headlights and ignition.
Researchers discovered that every affected device uses the same digital security key, comparable to protecting millions of devices with the password "1234" while preventing owners from changing it. Once the shared key is extracted from the official app, it can be used to send commands to any vulnerable vehicle within Bluetooth range.
Many drivers may not realize the hardware is installed in their car because dealerships sometimes leave it in place even when buyers decline the paid security service. Owners can check for a KARR or SWDS sticker on the driver-side window or a small blinking button beneath the dashboard.

The flaw does not allow an attacker to remotely start a vehicle or control one that is already moving. However, researchers warned that silently unlocking the doors removes one of the biggest obstacles a car thief faces.
Once inside, criminals could connect tools ordinarily used by locksmiths to the vehicle and create a working key within minutes, then start the engine and drive away.
How the system works
The system was originally designed to help dealerships manage inventory and protect cars from theft while on sales lots. Installed underneath the dashboard on the driver's side, it connects to a smartphone app through Bluetooth and performs functions similar to a key fob, letting authorized users lock or unlock the doors, sound the horn, flash the headlights and stop the engine from starting if it is not already running.
Dealerships often market app access as a paid security upgrade when a car is sold, but researchers found the hardware can remain connected and active even when a customer refuses the service, meaning some drivers could be carrying a vulnerable device without knowing it exists.
The team also found that public databases contain location information connected to vehicles fitted with the devices. That data could potentially allow someone to track a specific car, determine where it is regularly parked, and then move within Bluetooth range to target it.
How the flaw was found
UC San Diego researchers began investigating the systems after noticing unfamiliar Bluetooth signals in 2018 while searching for credit card skimmers hidden inside gas pumps. The signals were eventually traced to devices made by Acrisure and Rockledge, another vehicle security and insurance company.
Researchers said Rockledge devices may have a separate vulnerability, though exploiting it would be more difficult, requiring an attacker to be nearby when a driver used the system, record the digital exchange and replay it later. The team said it had been unable to confirm those findings with Rockledge because the company had not responded to its disclosure at the time the report was written.
The researchers withheld technical details that could help criminals reproduce the attack. They also reported the vulnerabilities to the manufacturers, relevant vendors and the National Highway Traffic Safety Administration.
What owners should do
Acrisure has released a firmware update intended to fix the KARR-SWDS flaw, but it will not automatically be delivered through Honda, Toyota, Mazda, Ford or Jeep. Because the system is aftermarket equipment rather than factory-installed technology, affected owners must update it themselves through the KARR app.
Aaron Schulman, a professor in UC San Diego's Department of Computer Science and Engineering and one of the study's senior authors, said many car owners do not even know their vehicle is vulnerable, and that the team wanted to make sure they were aware by publishing the study.
Drivers who find a KARR or SWDS label should download or open the official KARR Security app, connect it to the device and install the latest firmware. Anyone unable to identify or update the system should contact the dealership that sold the car or KARR customer support.
Researchers warned owners not to attempt to remove the hardware themselves. Yibo Wei, a UC San Diego computer science doctoral student and co-first author of the paper, said removing the devices is not trivial, since it requires opening up the dashboard and cutting and reconnecting wires that are deeply intertwined with the car's computers and ignition system.
The team argues that future Bluetooth security systems should require someone to physically press a button inside the vehicle before a new smartphone can connect.


