KARR vehicle owners, follow these instructions from Acrisure to update your firmware

Evaluating the Security of BLE-controlled Aftermarket Car Security Systems

A research study of aftermarket Bluetooth Low Energy systems that discovered critical vulnerabilities that allow malicious smartphone apps to unlock, immobilize, remotely start, and otherwise control vehicles. We estimate over two million vehicles are vulnerable and all owners need to manually update their firmware.

Summary

Aftermarket BLE remote control systems are installed by car dealers or individuals to add app-based vehicle control. We discovered six aftermarket systems in current use and analyzed their BLE application-layer security. We identified critical vulnerabilities in three systems, including two dealer-installed systems, and estimate that over two million vehicles are exposed to attack.

We also show that targeted BLE remote attacks are practical because these devices broadcast BLE advertisements that can be found locally or through crowdsourced Bluetooth scanning databases. Our disclosures prompted one aftermarket vendor to significantly improve BLE security in its dealer-installed system.

Systems Studied

We analyzed six aftermarket BLE automotive remote control systems: KARR, CarLink, Rockledge, DS4, EvoStart, and Linkr. Each system implements its own application-layer BLE security protocol.

At the time of the study, three systems had robust security: DS4, EvoStart, and Linkr. However, three systems, KARR, CarLink, and Rockledge, had critical pairing or authentication vulnerabilities that could allow unauthorized control of vehicle functions.

Impact

Vulnerable aftermarket systems are spliced into sensitive vehicle wiring, including:

  • Door locks
  • Horn
  • Lights
  • Immobilizer
  • CAN bus
  • Ignition

Owners may not know that an active aftermarket BLE system is installed in their vehicle, especially when the system was pre-installed by a dealer and never activated by the owner.

We estimate that more than two million vehicles have a vulnerable dealer-installed aftermarket BLE system and that tens of thousands of vehicles have vulnerable remote-start systems. Vulnerable devices are deployed across the United States, Canada, and beyond through resale in used car markets.

Full Technical Paper

BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems USENIX Security 2026

Jerry Yu* (Former student), Yibo Wei*, Sumanth Rao, Mohak Vaswani, Jefferson Chien (Former student), Christian Dameff, Nishant Bhaskar (Former student), and Aaron Schulman.

Disclosure

We practiced responsible disclosure with the vendors of KARR, CarLink, and Rockledge, and filed a report with the US National Highway Traffic Safety Administration describing the KARR vulnerability. We do not publish the details needed to exploit the pairing, authentication, or encryption vulnerabilities.

We disclosed KARR vulnerabilities on January 21, 2025. KARR met with us shortly after our disclosure and took several initial mitigation steps, then released a firmware update for all affected vehicles on July 20, 2026. KARR vehicle owners should follow Acrisure's firmware update instructions. We disclosed CarLink and Rockledge vulnerabilities to CarLink on July 31, 2025, and disclosed Rockledge vulnerabilities directly to Rockledge on December 17, 2025.

Contact

Contact email: bleauto-g@ucsd.edu

Team

This study was performed by researchers at the University of California, San Diego.

External Links

Update History