# One Shared Key, Every Car: The Bluetooth Flaw That Unlocks KARR Anti-Theft Systems


## The Threat


Dealer-installed automotive security systems are supposed to be the last line of defense against vehicle theft. The KARR BT and DR-100 devices — sold through car dealerships as aftermarket anti-theft protection under the Acrisure Protection Group brand — were doing the opposite. A hard-coded Bluetooth authentication key shared across every affected device meant that anyone within wireless range could authenticate as a legitimate controller and issue commands directly to the vehicle.


The flaw, CVE-2026-18411, is about as fundamental as security failures get: the same cryptographic key baked into firmware across an entire product line. An attacker doesn't need to steal credentials, brute-force a PIN, or exploit a complex vulnerability chain. They just need the key — and once it's extracted from any one device, it works on all of them. Researchers from UC San Diego demonstrated commands including door unlocking and engine immobilization, which means this isn't just a car alarm bypass. Someone with the right tool could lock you out of your own vehicle, or strand it.


Bluetooth Low Energy typically has an effective range of 10–30 meters in open environments, occasionally stretching further with directional antennas. That puts any KARR-equipped vehicle in a parking garage, shopping center, or street-level parking spot within practical attack range of a laptop and a commodity BLE adapter. No physical access to the vehicle required.


## Severity and Impact


| Field | Details |

|---|---|

| CVE | CVE-2026-18411 |

| CWE | CWE-321 — Use of Hard-coded Cryptographic Key |

| CVSS 3.1 Score | 8.1 (HIGH) |

| CVSS 3.1 Vector | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |

| CVSS 4.0 Score | 7.2 (HIGH) |

| CVSS 4.0 Vector | CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |

| Attack Vector | Adjacent (Bluetooth range) |

| Attack Complexity | Low |

| Authentication Required | None |

| User Interaction | None |

| Critical Sector | Transportation Systems |


The adjacent-network attack vector is the main mitigating factor keeping this just below the critical threshold. Physical proximity is still required — this isn't remotely exploitable over the internet. But "requires Bluetooth range" is not much of a barrier when the target is parked on a public street.


## Affected Products


Acrisure Protection Group

  • KARR BT — all firmware versions prior to July 20, 2026 release
  • DR-100 — all firmware versions prior to July 20, 2026 release

  • Both devices are dealer-installed automotive anti-theft systems marketed under the KARR Security System and SWDS brands.


    ## Mitigations


    Patch now. Acrisure released a firmware update on July 20, 2026, that addresses this vulnerability. Vehicle owners with KARR BT or DR-100 systems should update immediately via the official instructions at karrsecurity.com/karr-security-firmware-update-instructions.


    For fleet operators and dealerships with large numbers of vehicles equipped with these devices, prioritize high-value or high-visibility inventory first — vehicles regularly parked in public or high-traffic areas carry the most exposure until patched.


    Beyond the immediate patch:


  • Check with your dealer if you're unsure whether your vehicle has one of these systems installed. KARR and DR-100 are dealer-installed, so many owners may not know they have them.
  • Fleet managers should audit which vehicles in their inventory carry KARR/DR-100 hardware and track firmware update completion centrally.
  • Do not rely on the anti-theft system as a sole security control while unpatched — physical steering wheel locks or GPS tracking provide parallel protection that doesn't share the same Bluetooth attack surface.

  • CISA's standard ICS guidance applies here: minimize network exposure for connected vehicle systems and isolate control networks behind firewalls where infrastructure allows.


    ## References


  • [CISA ICS Advisory — Acrisure KARR BT and DR-100](https://www.cisa.gov/news-events/ics-advisories/)
  • [KARR Security Firmware Update Instructions](https://www.karrsecurity.com/karr-security-firmware-update-instructions)
  • [CVE-2026-18411 Details](https://www.cve.org/CVERecord?id=CVE-2026-18411)
  • [CWE-321: Use of Hard-coded Cryptographic Key](https://cwe.mitre.org/data/definitions/321.html)
  • [CISA ICS Security Best Practices](https://www.cisa.gov/ics)

  • ---


    ## HackWire Analysis


    The academic team from UC San Diego that found this vulnerability — eight researchers including Aaron Schulman, Christian Dameff, and Nishant Bhaskar — has a track record with wireless automotive security. This isn't a one-off finding from a bug bounty hunter who stumbled onto something. These are researchers systematically working through connected vehicle attack surfaces, and the KARR flaw fits a pattern they and others have documented repeatedly: aftermarket dealer accessories with dramatically weaker security postures than the vehicles they're meant to protect.


    That gap is the real story here. Automakers have spent significant resources hardening factory keyless entry and immobilizer systems. The replacement cycle for those systems is years-long, and the security investments are substantial. Meanwhile, a dealer can install an aftermarket anti-theft system — often upsold in the finance office — and that device ships with a single hard-coded Bluetooth key shared across the entire product line. The asymmetry is remarkable.


    The engine immobilization command is the detail that should get fleet operators and insurers paying attention. Vehicle theft via relay attacks on key fobs is already a well-documented problem. A vulnerability that lets someone remotely immobilize a vehicle within Bluetooth range introduces a different threat category entirely: targeted disruption. High-value cargo trucks, rideshare fleets, and emergency vehicles all represent scenarios where an adversary might want to strand a specific vehicle rather than steal it.


    The patch is out. But these systems are dealer-installed, which means update distribution depends on customers learning about the issue and returning to a dealership or following firmware instructions that many ordinary vehicle owners won't know exist. That gap between "patch released" and "patch deployed across all affected hardware" is where real-world risk lives longest.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)