● Vulnerabilities

2.2 Million Vehicles With Aftermarket Security Systems Vulnerable to Bluetooth Hijacking

July 24, 2026 · snewle
2.2 Million Vehicles With Aftermarket Security Systems Vulnerable to Bluetooth Hijacking

Researchers at the University of California San Diego have uncovered serious security flaws affecting millions of vehicles equipped with aftermarket security systems. The Bluetooth vehicle hijacking vulnerabilities impact at least 2.2 million cars fitted with dealer-installed KARR and SWDS security systems, allowing attackers within Bluetooth range to remotely unlock doors or prevent stopped vehicles from starting.

According to an advance look at the research published by UCSD this week, the vulnerabilities exist in security systems that were installed by dealerships rather than being factory-installed by vehicle manufacturers. These aftermarket systems, intended to provide additional protection against theft, ironically create new attack vectors that could be exploited by malicious actors in proximity to targeted vehicles.

What Security Systems Are Affected?

The vulnerable security systems identified in the research are KARR and SWDS products that were purchased and installed through California dealerships. These dealer-installed systems are separate from the factory security features that come standard with most modern vehicles. The 2.2 million figure represents a significant number of vehicles that could potentially be compromised through these Bluetooth-based attacks.

How Do the Bluetooth Attacks Work?

The attacks exploit weaknesses in the Bluetooth connectivity features of the KARR and SWDS security systems. Researchers found that attackers operating within Bluetooth range of vulnerable vehicles could execute commands to unlock doors or interfere with the vehicle’s ability to start after being stopped. The proximity requirement means attackers would need to be relatively close to the target vehicle, but this still presents a serious security concern in parking lots, driveways, and other common vehicle storage locations.

What Does This Mean for Vehicle Owners?

The discovery highlights ongoing challenges in automotive cybersecurity, particularly with aftermarket systems that may not undergo the same rigorous security testing as factory-installed components. Vehicle owners in California who had these security systems installed at dealerships should be aware of the potential vulnerabilities. The full research paper from UCSD, which will provide more detailed technical information about the vulnerabilities and potential mitigations, has not yet been released at the time of the advance publication.

Source: DataBreaches.net