Evaluating the Security of BLE-controlled Aftermarket Car Security Systems
A research study of aftermarket Bluetooth Low Energy systems that discovered critical vulnerabilities that allow malicious smartphone apps to unlock, immobilize, remotely start, and otherwise control vehicles. We estimate over two million vehicles are vulnerable and all owners need to manually update their firmware.
Summary
Aftermarket BLE remote control systems are installed by car dealers or individuals to add app-based vehicle control. We discovered six aftermarket systems in current use and analyzed their BLE application-layer security. We identified critical vulnerabilities in three systems, including two dealer-installed systems, and estimate that over two million vehicles are exposed to attack.
We also show that targeted BLE remote attacks are practical because these devices broadcast BLE advertisements that can be found locally or through crowdsourced Bluetooth scanning databases. Our disclosures prompted one aftermarket vendor to significantly improve BLE security in its dealer-installed system.
Systems Studied
We analyzed six aftermarket BLE automotive remote control systems: KARR, CarLink, Rockledge, DS4, EvoStart, and Linkr. Each system implements its own application-layer BLE security protocol.
At the time of the study, three systems had robust security: DS4, EvoStart, and Linkr. However, three systems, KARR, CarLink, and Rockledge, had critical pairing or authentication vulnerabilities that could allow unauthorized control of vehicle functions.
Impact
Vulnerable aftermarket systems are spliced into sensitive vehicle wiring, including:
- Door locks
- Horn
- Lights
- Immobilizer
- CAN bus
- Ignition
Owners may not know that an active aftermarket BLE system is installed in their vehicle, especially when the system was pre-installed by a dealer and never activated by the owner.
We estimate that more than two million vehicles have a vulnerable dealer-installed aftermarket BLE system and that tens of thousands of vehicles have vulnerable remote-start systems. Vulnerable devices are deployed across the United States, Canada, and beyond through resale in used car markets.
Full Technical Paper
BLE Theft Auto: Evaluating the Security of Aftermarket BLE-based Automotive Remote Control Systems USENIX Security 2026
Jerry Yu* (Former student), Yibo Wei*, Sumanth Rao, Mohak Vaswani, Jefferson Chien (Former student), Christian Dameff, Nishant Bhaskar (Former student), and Aaron Schulman.
Disclosure
We practiced responsible disclosure with the vendors of KARR, CarLink, and Rockledge, and filed a report with the US National Highway Traffic Safety Administration describing the KARR vulnerability. We do not publish the details needed to exploit the pairing, authentication, or encryption vulnerabilities.
We disclosed KARR vulnerabilities on January 21, 2025. KARR met with us shortly after our disclosure and took several initial mitigation steps, then released a firmware update for all affected vehicles on July 20, 2026. KARR vehicle owners should follow Acrisure's firmware update instructions. We disclosed CarLink and Rockledge vulnerabilities to CarLink on July 31, 2025, and disclosed Rockledge vulnerabilities directly to Rockledge on December 17, 2025.
Contact
Contact email: bleauto-g@ucsd.edu
Team
This study was performed by researchers at the University of California, San Diego.
- Jerry Yu (Former student)
- Yibo Wei
- Sumanth Rao
- Mohak Vaswani
- Jefferson Chien (Former student)
- Christian Dameff
- Nishant Bhaskar (Former student)
- Aaron Schulman
External Links
- A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now - WIRED, Andy Greenberg
- I Stole a Car By Hacking This Hidden Device - WIRED, Andy Greenberg
- Anyone in Bluetooth Range Can Unlock Cars, Kill Engines Through Alarms Owners May Never Have Paid For - The Drive, Adam Ismail
- 2 million cars at risk of sneaky Bluetooth hack that unlocks doors - Popular Science, Mack DeGeurin
- Millions of California-bought cars can be hijacked via Bluetooth - The Register, Brandon Vigliarolo
- Millions of cars could be tracked and unlocked by a hidden security flaw - Malwarebytes, Danny Bradbury
- KARR Bluetooth flaw exposes 2.2M cars to theft risk - CyberGuy, Kurt Knutsson
- UCSD researchers discover flaw in KARR anti-theft system affecting millions of SoCal drivers - KPBS, Alexander Nguyen
- Anti-theft device flaw risks 2.2M vehicles in Southern California - CBS 8, Esmeralda Perez
- This anti-theft auto system makes it easier to steal cars, UCSD professor finds - The San Diego Union-Tribune, Noelle Harff