California aftermarket car security systems vulnerable to Bluetooth hijacking via shared encryption key

Millions of vehicles with dealer-installed KARR/SWDS security systems use identical Bluetooth encryption keys, allowing attackers to unlock and start cars remotely.

Abstract representation of vehicle Bluetooth security vulnerability
AI-generated illustration · Sylvaris

Single key protects millions of vehicles

Researchers at UC San Diego discovered that aftermarket KARR and SWDS vehicle security systems installed by California dealerships all use the same Bluetooth encryption key. This design flaw affects millions of vehicles, allowing anyone with knowledge of the shared key to unlock, disable alarms, and start affected cars.

The vulnerability exists because the systems were designed with a single master key rather than unique keys per installation. This approach makes the entire deployed fleet vulnerable once the shared key becomes known.

Aftermarket installations create risk

The affected systems are not original manufacturer equipment but rather third-party security products installed by dealers, often as add-ons during vehicle purchase. This creates a supply chain risk where dealer-installed components introduce vulnerabilities that neither the vehicle manufacturer nor the buyer expected.

Vehicle owners may not know their cars have these systems installed or that they introduce security risks. The Bluetooth-based design was intended to add convenience through smartphone control but instead created a remote attack surface affecting an entire product line.

sources
more in Security
Zimbra zero-click vulnerability exploited by Russian state hackers for email theft The Russian group Laundry Bear combines phishing with a patched Zimbra flaw to access email without user interaction, targeting organizations still running vulnerable servers. Oracle ships 1,449 security patches in quarterly update as AI-driven vulnerability discovery accelerates The patch volume reflects AI tools finding vulnerabilities faster than human researchers, forcing defenders to manage larger workloads quarterly. GitHub reduces public bug bounty payouts as AI-generated reports overwhelm security team GitHub is lowering public bug bounty rewards and restricting first-time researcher access after AI-generated security reports created unsustainable volume for the security team to triage.