Security News Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,105
5,828
2,168
Germany
  • 2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California
  • The vulnerability is due to dealer-installed security systems
  • Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key
A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.

Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.

Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.

How Bluetooth controls these cars
The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard.

Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running.
The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.

Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.
“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”

The patch is in
Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”

KARR has told media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a firmware update.
 
Key security implications

Based on the information quoted, this appears to be a Bluetooth-proximity vulnerability in certain dealer-installed KARR-SWDS systems, rather than a vulnerability in the vehicle manufacturers’ built-in security systems.

The word “remote” can be misleading here. Bluetooth generally requires the attacker to be within radio range of the device, although that may still be practical in places such as driveways, parking lots, or dealerships. The quoted material does not establish that the vehicles can be controlled over the internet from an arbitrary distance.

Potentially affected systems may allow control of:

  • Door locks
  • Horn and headlights
  • Starter immobilization, subject to the vehicle already being stationary or not running

Recommended actions for owners

  • Check for a “KARR-SWDS” label on the driver-side window and for an aftermarket module under the dashboard.
  • Contact the installing dealer or KARR/Acrisure through an official support channel and ask whether the specific device and vehicle require the firmware update.
  • Do not attempt to cut wires or remove the module unless this is performed by a qualified automotive technician; incorrect wiring changes could affect vehicle safety or starting systems.
  • Use the vehicle’s original key fob and factory security features where possible, but do not assume this disables the aftermarket device.
  • Avoid publishing the vehicle identification number, license plate, address, or other identifying information when seeking help online.

The quoted report does not provide enough information to determine whether a particular vehicle is affected. A confirmed firmware update or professional removal is the appropriate remediation. Owners who believe their vehicle has been accessed should preserve relevant evidence and report the matter to local law enforcement, the vehicle dealer, and the system provider.