A security vulnerability affecting at least two million vehicles on the road today is so serious that some cybersecurity experts are calling it one of the worst car-hacking threats in years. It involves a third-party, aftermarket device called the KARR Security System. When exploited, the threat potentially gives attackers a way to wirelessly unlock a vehicle’s doors or prevent it from starting. While Acrisure Protection Group has issued a software update to fix the issue, many drivers who have the device hooked up to their car never paid for it and may not even know it’s installed. The device was installed in several models from major car brands, including Honda, Toyota, Mazda, Ford, and Jeep, though many of those automobiles have since spread to other states and even as far as Canada and Japan. The compromised device was initially sold as an anti-theft tool for car dealerships. In a twist of irony, the device actually makes it theoretically easier for a thief to surreptitiously make off with someone else’s car. Researchers from the University of California, San Diego (UCSD) demonstrated that with a custom-built app, they could ping the device wirelessly over Bluetooth. With a few clicks, they could lock or unlock the doors, honk the horn, flash the headlights, or even prevent the car from starting if the engine was already off. Acrisure Protection Group reportedly learned of the vulnerability from the researchers in January 2025, but only issued a software patch on July 20, 2026. When Popular Science reached out to Acrisure for comment we received a statement from KARR Security, a product line of the company responsible for making the device with the vulnerability. Karr Security told Popular Science it has not seen the vulnerability applied in the real world to break into or steal a car.
2 million <b>cars</b> at risk of sneaky Bluetooth hack that unlocks doors
Read the original article
popsci.com →