San Diego

San Diego Car Alarms Hacked: Dealer Add-Ons Put 2 Million Rides At Risk

AI Assisted Icon
Published on July 22, 2026
San Diego Car Alarms Hacked: Dealer Add-Ons Put 2 Million Rides At RiskSource: Jacky Nelson on Unsplash

Millions of cars, many of them rolling off Southern California lots, may have an anti-theft system that hackers can flip into a remote-control toy. University of California San Diego researchers say a dealer-installed Bluetooth gadget wired into vehicles can be hijacked nearby to unlock doors, trigger alarms or even keep a parked car from starting.

The team estimates at least 2.2 million KARR/SWDS units are in circulation, and the product’s operator has pushed out a firmware update that owners must install themselves through a smartphone app. The finding has led to urgent warnings for drivers, particularly in the San Diego region, where dealerships frequently added the devices to cars before sale.

Researchers find a single shared key undercuts security

UC San Diego computer scientists say they reverse‑engineered the KARR Security System and discovered that Bluetooth‑enabled units rely on one hardcoded authentication key shared across devices. Once they extracted that key, they found they could spoof the radio commands the alarm accepts, unlocking doors, disarming alarms, honking horns and blocking engine starts when the vehicle is off.

The researchers used crowdsourced radio‑signal databases and device serial numbers to estimate how widely the hardware is deployed and disclosed their findings to federal regulators, according to UC San Diego.

Proof-of-concept demos show how an attacker could act

In published demos, the UCSD team showed how little sophistication an attacker might need. Using a homemade Android app to impersonate the official KARR client, they sent spoofed commands to nearby units, remotely unlocking cars, setting off synchronized horn-and-light chaos and leaving parked vehicles unable to start.

Reporters and outside researchers described the flaw as severe, in part because many car owners do not even realize the hardware is installed and because automakers themselves cannot patch the vehicle’s built-in systems to fix it, as detailed by WIRED.

How to check and install the patch

The fix does not require tearing into your dashboard, but it does require action from owners. The company has issued a firmware update that must be applied through the KARR Security smartphone app while the car is powered on.

Owners who already use the app should see an update notice. Those who do not can download it and follow the “Customer Service” → “Firmware Update” menu to apply the patch, which researchers say typically takes one to two minutes. The update steps and support contacts are posted on the company’s website, according to KARR Security.

Dealers installed the systems, sometimes without owners' consent

According to local reporting and the UCSD analysis, dealerships often install KARR units on cars in their inventory to protect vehicles on the lot, then leave the hardware active after a sale, even when buyers decline the add-on. Several Southern California dealerships did not respond to questions about how they disclose or remove the devices, the San Diego Union‑Tribune reported.

Many affected cars carry a small KARR or SWDS sticker on the driver’s window, which makes the risk especially concentrated in this region but not limited to it, according to The San Diego Union‑Tribune.

Regulators notified and researchers will present full findings

The research team says it has notified the National Highway Traffic Safety Administration and plans to present full technical details at the DEF CON and USENIX Security conferences next month.

“We’re trying to get the word out that you need to check your car for this device and manually patch it now,” researcher Stefan Savage’s colleague Aaron Schulman told WIRED. Security experts say the episode is a sharp reminder that third-party dealer add-ons can quietly create national safety and theft risks, even when they are marketed as protection.