Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Millions of California Cars Vulnerable to Bluetooth Hijacking, Say Researchers

Security researchers at the University of California San Diego have uncovered a critical vulnerability in aftermarket car security systems, potentially affecting millions of vehicles. The flaw allows unauthorised access and control via Bluetooth due to a shared 'secure key' across all units.

  • Millions of cars in California, equipped with KARR/SWDS security systems, are vulnerable.
  • Researchers found all systems use the same 'secure key' for Bluetooth communication.
  • This flaw allows potential carjacking or remote control of vehicle functions.
  • The affected systems are dealer-installed aftermarket additions, not factory defaults.
  • The University of California San Diego team published the findings.

A significant security flaw in popular aftermarket car alarm systems could leave millions of vehicles vulnerable to hijacking, according to new research from the University of California San Diego (UCSD). The study reveals that KARR/SWDS security systems, widely installed by car dealers across California, all utilise an identical 'secure key' for their Bluetooth communication, making them susceptible to unauthorised access.

The researchers demonstrated that this shared key allows anyone within Bluetooth range to potentially connect to a vulnerable vehicle's security system. Once connected, an attacker could disable the alarm, unlock doors, and even start the engine, effectively enabling car theft or remote interference with the vehicle's functions. The discovery raises serious concerns for vehicle owners who have these systems installed, as it bypasses traditional security measures.

These KARR/SWDS systems are typically added by dealerships as an optional security upgrade, rather than being part of the manufacturer's standard vehicle package. This widespread installation practice, particularly in California, means a large number of car owners could be unknowingly at risk. The UCSD team's findings highlight a critical oversight in the design and implementation of these aftermarket solutions, where standardisation for ease of deployment has inadvertently created a massive security loophole.

While the research specifically focused on systems prevalent in California, the implications could extend further if similar security system designs are used elsewhere. The study, which has been peer-reviewed, underscores the growing importance of scrutinising the security of all vehicle components, not just those integrated by manufacturers. It also serves as a stark reminder that convenience in mass deployment should never come at the expense of robust security protocols.

The researchers have urged owners of vehicles fitted with KARR/SWDS systems to contact their dealerships for advice on potential mitigation or removal. The full extent of vehicles affected is still being assessed, but given the popularity of these dealer-installed options, the numbers are expected to be substantial.

Why this matters: While the immediate focus is on California, this research highlights a broader issue with aftermarket vehicle security and the potential for shared vulnerabilities. UK car owners should be aware of the security of any non-manufacturer installed systems.

What this means for you: What this means for you: If you have an aftermarket security system installed in your vehicle, especially one not provided by the manufacturer, it would be prudent to verify its security features and ensure it doesn't share common vulnerabilities identified in this research.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.