A study by UCSD researchers has revealed a critical security flaw in the KARR alarm system, which is installed in over 2 million vehicles.The KARR device, designed for car alarms, uses Bluetooth signals that can be intercepted and exploited by hackers.
Researchers discovered that the device's authentication protocol is so weak that an attacker could reverse-engineer its app and gain access to every vehicle equipped with the system.This vulnerability persists even after the car is turned off, leaving vehicles exposed for up to 10 minutes.Hackers can activate the KARR device remotely via radio commands, triggering a brief horn beep and light flicker as subtle indicators of compromise.However, users who paid dealers to enable the alarm system receive no warnings.
The researchers used crowdsourced data from WiGLE to estimate the scale of the issue, finding KARR-enabled vehicles in nearly every location they scanned.This widespread vulnerability raises concerns about vehicle tracking and potential theft or sabotage.The UCSD team emphasizes the need for public awareness and urgent fixes to mitigate risks to millions of drivers.
Original title: A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
The AI system has determined that this news is not clickbait/sensationalist: : The original title is factual and directly references the core issue without sensationalism, focusing on the technical vulnerability rather than alarming language. This has coincided with the opinion of the majority of users.