Researchers at the University of California San Diego discovered a Bluetooth vulnerability in dealer-installed anti-theft devices that could compromise 2.2 million vehicles [1].

This flaw is significant because it turns a security feature into a point of entry for attackers. By exploiting the lack of proper authentication in the Bluetooth implementation, unauthorized users in close proximity to a vehicle can remotely control critical functions.

The vulnerability affects KARR and SWDS security devices [2]. Researchers said attackers can use the flaw to unlock vehicle doors, disable the ignition, or trigger the horn [2]. Because these devices are often installed by dealerships rather than the original manufacturer, the scope of the risk extends across various car brands and models.

Approximately 2.2 million vehicles are at risk [1], with a notable concentration of affected cars located in Southern California [3]. The researchers released their findings last week, highlighting that the Bluetooth protocol used by these specific devices does not require a secure handshake, or verified identity, before executing commands [2].

This means an attacker does not need a physical key or a stolen signal to gain access. They only need to be within the Bluetooth signal range to send the commands that unlock the car or manipulate the ignition [2]. The vulnerability exists specifically within the third-party hardware installed by dealers, not the vehicle's own factory security system [3].

Vehicle owners who had these specific anti-theft systems installed are advised to check with their dealerships for potential patches or hardware removals. The research team said the gap in authentication was the primary cause of the security failure [2].

Attackers can use the flaw to unlock vehicle doors, disable the ignition, or trigger the horn.

This incident highlights a growing security gap where third-party 'add-on' electronics create new attack vectors for vehicles. While manufacturers focus on securing factory systems, dealer-installed hardware often lacks the same level of rigorous cybersecurity auditing, potentially neutralizing the primary security of the car.