Application security

Millions of vehicles vulnerable to Bluetooth car theft attacks

Millions of vehicles equipped with dealer-installed KARR and SWDS security systems are susceptible to Bluetooth-based attacks that could allow unauthorized access or prevent vehicles from starting. Researchers at the University of California San Diego discovered that these systems share a common security flaw, based on information published by The Register.

The vulnerability affects approximately 2.2 million vehicles, primarily those purchased in Southern California over the last nine years from Honda, Toyota, Mazda, Ford, and Jeep dealerships, though resales have spread affected vehicles nationwide and even internationally. The flaw lies in a shared security key used by KARR and SWDS devices, allowing anyone within five yards with a Bluetooth-enabled device to unlock doors, honk the horn, flash headlights, or disable the ignition. Even vehicles with inactive KARR/SWDS contracts remain vulnerable, as removing the devices is a complex process involving dashboard disassembly. KARR Security has released a firmware update to address the issue, though it is unclear if they are proactively notifying customers. The company claims only a small percentage of devices with specific Bluetooth components are affected and that the real-world risk is low.

Source: The Register

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds