Aftermarket Anti-Theft Device Owners Don’t Know How Vulnerable They Are To Hacking

🔔 Read us on Telegram — don’t miss the latest automotive news → t.me/motorhub_en

A team of University of California San Diego researchers has discovered a vulnerability in the KARR Security System, an aftermarket anti-theft device used in over two million vehicles. The device, which provides features such as remote lock/unlock, engine immobilization, and GPS tracking, can be hacked using a reverse-engineered mobile app, allowing attackers to control every function of the system.

Aftermarket Anti-Theft Device Owners Don't Know How Vulnerable They Are To Hacking

This includes unlocking doors, immobilizing the engine, and even triggering the car’s horns and lights. The vulnerability is due to the use of the same authentication key across all KARR devices and an open Bluetooth connection, even in deactivated units.

Aftermarket Anti-Theft Device Owners Don't Know How Vulnerable They Are To Hacking

The researchers demonstrated several exploits, including unlocking a car at a stop light and paralyzing a parked car. While the manufacturer, Acrisure Protection Group, has released a firmware update to address the issue, it took 18 months to respond to the researchers’ findings.

The vulnerability affects vehicles from various manufacturers, including Honda, Toyota, Mazda, Ford, and Jeep, and can be found in cars sold in Southern California and resold on the second-hand market across the United States, Canada, and Japan. Owners of vehicles with the KARR system are advised to download and install the update through the KARR app to protect their cars from potential hacking.

Aftermarket Anti-Theft Device Owners Don't Know How Vulnerable They Are To Hacking

📱 Follow our Telegram channel for daily updates

Source: Jalopnik (Auto Culture & Tuning) (jalopnik.com)