Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Millions of California-Bought Cars Can Be Hijacked via Bluetooth: A Widespread Vulnerability Exposed


Millions of California-bought cars can be hijacked via Bluetooth due to a widespread vulnerability in aftermarket dealer-installed security systems. Researchers at UCSD have discovered that all KARR and SWDS devices rely on the same secure key, making them susceptible to attacks via Bluetooth.

  • Vulnerable aftermarket security systems installed in millions of US vehicles are susceptible to Bluetooth-based attacks.
  • The devices rely on the same secure key, making it possible for hackers to unlock cars, honk horns, and flash headlights.
  • Awareness about potential risks associated with aftermarket devices is crucial, as consumers may unknowingly install vulnerable systems.
  • Regular software and firmware updates are essential to mitigate such vulnerabilities.


  • Millions of vehicles sold in the United States, including those purchased in California, have been found to be vulnerable to exploitation through Bluetooth technology. According to researchers at the University of California San Diego (UCSD), a significant number of aftermarket dealer-installed security systems, known as KARR and SWDS devices, are susceptible to attacks via Bluetooth.

    The study, which was conducted by UCSD compsci graduate Jerry Yu and PhD candidate Yibo Wei, reveals that these devices rely on the same secure key, making it possible for anyone with knowledge of this key and a device with a Bluetooth connection to unlock the vehicle, honk the horn, flash the headlights, or even prevent the car from starting. This vulnerability was discovered serendipitously by the researchers during their research on credit card skimmers.

    The affected vehicles were primarily purchased in Southern California over the past nine years from dealerships of Honda, Toyota, Mazda, Ford, and Jeep. However, due to the secondary market resales, these vulnerable vehicles can be found throughout the US and even as far away as Japan. The researchers also discovered a public database that stores information about equipped vehicles, which has raised concerns about the potential for widespread exploitation.

    In response to the vulnerability, KARR Security has released a firmware update for affected devices, which can be installed by both active customers and those with an inactive security system. However, it is unclear whether the company is notifying customers of the need to update their security system.

    The researchers emphasized that removing the devices from the vehicle is not a trivial task, requiring the opening up of the dashboard and cutting and reconnecting wires deeply intertwined with the car's computers and ignition system. The vulnerability was deemed "highly complex" by KARR Security, but they have developed a firmware update to address the issue.

    While KARR Security claims that only a small percentage of devices with certain Bluetooth-related components are affected, the researchers found that all KARR-SWDS devices rely on the same secure key, making them vulnerable to attack. The discovery has raised concerns about the potential for widespread exploitation and highlighted the need for manufacturers to prioritize security in their products.

    The vulnerability highlights the importance of regularly updating software and firmware, as well as the need for consumers to be aware of potential risks associated with aftermarket devices installed on their vehicles. As technology continues to advance, it is essential for manufacturers and regulators to stay ahead of emerging threats and develop effective measures to mitigate them.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/Millions-of-California-Bought-Cars-Can-Be-Hijacked-via-Bluetooth-A-Widespread-Vulnerability-Exposed-ehn.shtml

  • https://www.theregister.com/security/2026/07/23/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth/5277315


  • Published: Thu Jul 23 11:37:02 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us