Urgent Alert: Vulnerability in Hidden Device Could Leave U.S. Cars Exposed to Hacking – Here’s How to Patch It!

As cars have transformed into complex computing machines, owners now find themselves required to consider security updates much like they would for a laptop or smartphone. Unfortunately, many are unaware of a significant vulnerability tied to a third-party device already installed in their vehicles—specifically, the KARR Security System. This aftermarket car alarm has been fitted in over 2 million cars across the United States, creating a potential hacking opportunity for cybercriminals.

Researchers at UC San Diego recently uncovered that KARR’s Bluetooth-enabled device can be hacked by anyone within range, allowing intruders to unlock the car, disable alarms, and even disable the ignition—potentially leaving a driver stranded. The alarms are generally installed by car dealerships as a preventive measure against theft, but they remain in place even if the buyer chooses not to pay for them, leaving countless cars exposed to this risk.

Aaron Schulman, the lead researcher, emphasized the seriousness of this vulnerability. The ease with which a hacker can exploit it makes this issue one of the most alarming cyber threats in the automotive industry. In response to the findings, Acrisure Protection Group, the parent company of KARR, announced a firmware update aimed at resolving these security deficiencies. Owners of KARR-enabled vehicles can be alerted through the KARR Security smartphone app, which they can download on either Android or iOS.

The vulnerability stems from a shared authentication key across all KARR devices, which the UCSD researchers were able to extract and exploit. With this, they developed an app capable of sending commands to nearby KARR-equipped cars, demonstrating the capability to lock or unlock vehicles, honk horns, and activate lights, all with a simple button press. Notably, while the systems do not allow ignition start, this hack enables thieves to effortlessly enter and steal the vehicle using readily available tools.

The pervasive nature of these KARR devices complicates matters further. Even if a driver opts out of the alarm system, the device remains installed and can be activated discreetly. Drivers might only notice a brief beep or flicker when the device is triggered, which is far from adequate warning.

The researchers used various data sources to estimate over 2 million of these alarm systems are in use, leading to concerns not just about theft but also potential harassment, given the ease of remote activation of vehicle functions. Stefan Savage, a fellow researcher, highlighted the vulnerability as "probably the worst" car hacking threat encountered in a significant number of vehicles, especially since owners often lack knowledge or means to address the threat.

Acrisure’s response has been met with skepticism, particularly given their slow reaction to the uncovered vulnerability, which took nearly 18 months to patch after the researchers first reported it. This raises concerns about the effectiveness of their communication strategies, especially for reaching past vehicle owners who may have unwittingly bought used cars with KARR systems installed.

To identify if your vehicle has a KARR device, look for a sticker on the driver’s side window, often displaying “SWDS” as an additional indicator. While Southern California holds the highest concentration of KARR devices, the research team found installations across the nation and even beyond.

With the rapid evolution of car technology, securing vehicles from vulnerabilities like the KARR alarm should be a top priority for manufacturers and consumers alike. The call for awareness is clear: car owners need to understand what systems are installed in their vehicles and how to secure them. It’s essential to address these security flaws to prevent theft and protect the integrity of personal safety and property.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Article

Sheetz Transitions from VMware to New Solutions in Over 830 Locations

Next Article

Nvidia's Ambitious Vision: Dominating Every Chip Market in AI Data Centers

Related Posts