Новости компьютерной безопасности:

  Latest News

Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks

С сайта: Vulnerability(cybersecuritynews.com)

Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks

Author: Abinaya

A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization.

This issue, uncovered by researchers at the University of California, San Diego, highlights a growing risk associated with dealer-installed hardware that falls outside the traditional automotive security frameworks.

Dealerships commonly install the KARR system as a protective measure for vehicles on their lots before sale. However, in many cases, the hardware remains in vehicles even when buyers choose not to activate or pay for the service.

This practice has created a large, largely unaware user base of affected vehicles, many of which continue to emit Bluetooth signals despite being inactive.

KARR Bluetooth Vulnerability
According to the researchers, the vulnerability allows an attacker within Bluetooth range to issue commands to the vehicle’s alarm system.

These commands include locking or unlocking doors, turning off the alarm, triggering lights and horns, and preventing the engine from starting.

While the flaw does not enable remote driving or control of a moving vehicle, it significantly lowers the barrier for theft by granting silent access to the vehicle’s interior.

The root cause of this issue lies in a shared authentication key embedded in all KARR devices. By reverse-engineering the official KARR mobile application, researchers extracted this universal key.

They created a proof-of-concept Android app capable of impersonating legitimate users. Using this tool, they successfully demonstrated attacks on multiple vehicles without requiring device-specific exploits.

cyber security news
UCSD researchers mapped vulnerable KARR-equipped vehicles across the U.S. using crowdsourced WiGLE radio signal data (source : appleinsider )
Despite Acrisure Protection Group describing the KARR attack as complex and low-risk, researchers say it becomes straightforward once the key is known, making the technique scalable across all affected systems.

Mitigation efforts are complicated by the fact that KARR is not integrated into manufacturers’ native systems. Therefore, traditional over-the-air updates or manufacturer recalls do not apply.

According to an AppleInsider report, Acrisure released a firmware patch on July 20 after responsible disclosure in January 2025, but vehicle owners must manually check for KARR hardware and install the update through the KARR mobile app.

Beyond the risks of active exploitation, the vulnerability raises privacy concerns. The KARR system continuously emits identifiable Bluetooth signals while the vehicle is in use and for a short period after shutdown.

Researchers used the WiGLE wireless tracking database to estimate the widespread deployment of these systems. They demonstrated how historical signal data could potentially reveal vehicle movement patterns or frequently visited locations.

During a short drive near San Diego, the researchers detected signals from nearly 100 KARR-equipped vehicles, emphasizing how overlooked aftermarket systems can introduce substantial security gaps across millions of vehicles.

Vehicle owners are advised to check for KARR or SWDS branding, typically found on the driver’s side windows or beneath the dashboard.

Installing the KARR Security app and applying the latest firmware update is currently the primary mitigation method. For those unable to confirm the presence of the system or complete the update, contacting the dealership or KARR support is recommended.

This incident underscores a broader challenge in automotive cybersecurity, where third-party hardware can bypass established security controls, leaving both manufacturers and consumers with limited visibility and delayed response capabilities.

The Privilege Paths Attackers See That You Don’t: BeyondTrust Pathfinder Platform Does It for You -> Get Free Identity Security Assessment



#Bluetooth #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news

Оригинальная версия на сайте: Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.