HeadlinesBriefing favicon HeadlinesBriefing.com

KARR car alarm vulnerability: Patch with iPhone

AppleInsider •
×

Millions of drivers with dealer-installed KARR alarms are urged to update their systems via an iPhone app due to a critical Bluetooth vulnerability. This flaw allows nearby attackers to unlock or immobilize over 2.2 million vehicles. The KARR Security System is an aftermarket alarm often installed by dealerships, which can remain connected even if the service isn't purchased.

The vulnerability affects only the dealer-installed KARR hardware, not factory car systems or Apple software. Researchers at the University of California, San Diego, demonstrated that attackers within Bluetooth range could control vehicle functions. Acrisure Protection Group, the seller of KARR, released a firmware update on July 20 to address the issue.

Owners should download the KARR Security app, connect to their alarm, and select "firmware update." The vulnerability stems from a shared authentication key found within the KARR app, allowing a proof-of-concept app to command affected alarms. While the flaw doesn't permit remote starting or driving, it could grant unauthorized access to the vehicle's interior. Drivers can check for KARR or SWDS stickers on the window or a blinking light under the dashboard. The vulnerability was reportedly patched before researchers presented their findings at DEF CON and USENIX Security Symposium.