Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
A Hidden Dealer-Installed Alarm in 2 Million US Cars Could Be Hacked to Unlock, Track, or Disable Vehicles. A Patch Is Now Available

A device you never bought, hiding in your dashboard
Most car owners have never heard of the KARR Security System.
Researchers at UC San Diego, led by computer science professor Aaron Schulman, discovered that this aftermarket Bluetooth alarm has been wired into more than 2 million vehicles across the US, according to Wired. Dealers install it before a car ever reaches a buyer, as a theft deterrent for lots full of unsold inventory. When the car sells, the device typically stays in place, whether or not the new owner ever agreed to pay for it.
That means a huge number of American drivers have a third-party security gadget plugged into their vehicle's electronics that they didn't request, don't know exists, and have no way of monitoring on their own.
What the flaw actually lets a hacker do
Schulman's team found the KARR system had a severe vulnerability: anyone within Bluetooth range could send radio commands to the device and take control of core alarm functions. That includes silently unlocking the car, disabling the alarm, honking the horn, flashing the lights, or disabling the ignition entirely and stranding the driver.
"This is a system added to cars by dealers, and unfortunately it has a severe vulnerability that allows anyone to gain access to any of these cars," Schulman told Wired. "It's designed to make cars more secure, but ultimately it's created a vulnerability that needs to be patched immediately across millions of vehicles. We're trying to get the word out that you need to check your car for this device and manually patch it now."
The practical risk ranges from nuisance to genuinely dangerous. A car thief could unlock a vehicle without breaking a window. A stalker could track or immobilize someone's car. A stranded driver with a disabled ignition in a bad location isn't just inconvenienced, they could be in real danger, especially at night or in an isolated area.
The fix exists, but it's not automatic for everyone
Acrisure Protection Group, the company behind the KARR Security System, has rolled out a firmware update for the vulnerable Bluetooth model to close the security gap UCSD identified.
Owners who already have the KARR Security smartphone app installed should get a notification about the update, per the UCSD team's findings reported by Wired. But anyone who doesn't already have the app, which likely includes most people who bought a used car with the alarm still installed and never knew it was there, won't get an automatic push notice. They'll need to track down and install the KARR app themselves to receive the patch.
A security fix that depends on a driver already having installed an app for a device they didn't know existed doesn't reach everyone who's exposed.
The legitimate case for these devices, and the legitimate complaint
Dealer-installed theft deterrents exist for a reason. Lots full of unsold cars are a target, and an alarm system that can remotely track or disable a vehicle is a reasonable tool for that specific job. Nobody is arguing dealerships shouldn't protect their inventory.
The complaint isn't that the device exists. It's that a commercial anti-theft tool built for one purpose, protecting a dealer's lot, ends up permanently embedded in a private citizen's vehicle after the sale, without the buyer's informed consent, and without a clear disclosure process telling them it's there or how to manage it. That's a supply-chain and disclosure failure, not a conspiracy.
What owners should actually do
Car owners, especially anyone who bought a used vehicle in the last few years, should check under the dash or consult their dealer paperwork to see if a KARR Security System was installed. If it's there, the KARR Security app needs to be downloaded so the firmware patch can be applied.
The broader question this raises hasn't been answered yet: how many other dealer-installed, manufacturer-agnostic devices are sitting in American cars right now, wired into critical systems, with no clear owner notification process and no mandatory disclosure at point of sale. UCSD's research targeted one product. Nobody has published a comprehensive inventory of what else is out there.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.