safety security
The Anti-Theft Box Shared One Key With Millions of Cars
Researchers found a common Bluetooth key in dealer-installed KARR/SWDS systems; owners must use the app to install a July 20 patch.

Summary
Researchers found a common Bluetooth key in dealer-installed KARR/SWDS systems; owners must use the app to install a July 20 patch.
UC San Diego researchers say dealer-installed KARR/SWDS devices left at least 2.2 million vehicles vulnerable because every unit relied on the same cryptographic key. From within roughly five yards, an attacker who possessed that key could unlock doors or immobilize an engine; separate tools would still be needed to start and steal a vehicle. Manufacturer Acrisure released a firmware patch July 20, but owners must install it through the KARR app. The team disclosed the flaws to manufacturers, vendors, and the National Highway Traffic Safety Administration and withheld exploit details.
Why it matters
Researchers found a common Bluetooth key in dealer-installed KARR/SWDS systems; owners must use the app to install a July 20 patch.
Limits and context
No additional limitation was separately recorded.
Key claims
Researchers found a common Bluetooth key in dealer-installed KARR/SWDS systems; owners must use the app to install a July 20 patch.
Evidence: source-2026-07-22-001
Sources
- UC San Diego via Newswise: Dealer-installed car security vulnerabilityUniversity of California San Diego via Newswise · official announcement
Corrections
No corrections have been recorded for this story.