Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now security researchers from UC San Diego warn they can be hacked to unlock, track, and disable cars.
Car owners who already have the KARR Security smartphone app installed should receive an alert about the firmware update, the UCSD team says. Those who don’t have it installed will need to download the KARR Security System smartphone app (Android, iOS), connect it to their vehicle’s KARR alarm, then tap “customer service” and “firmware update.” Acrisure Protection Group, which sells the alarms, offers more detailed patching instructions on its website if you search online for “KARR security firmware update instructions.”
When WIRED reached out to Acrisure Protection Group about the KARR security flaw, a spokesperson responded in a statement, “The vulnerability described in [UCSD’s] research is highly complex and presents a low risk to customers under real-world conditions. Nevertheless, we responded promptly and developed a firmware update to address the issue.”
Despite Acrisure Protection Group’s claim to have patched the flaw “promptly,” it actually took close to 18 months to push out its patch. The UCSD researchers told the company about the vulnerability in January of last year, but the company didn’t offer a fix until just weeks ahead of UCSD’s planned presentations about its findings at the Defcon hacker conference and the Usenix security conference next month.
Whether the hacking technique presents a “low risk” to car owners, you can judge for yourself based on the demos we witnessed and tried ourselves.
Released on 07/22/2026
Click Here For The Original Source.
