Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Bluetooth Flaw in Dealer-Installed KARR Security Devices Puts 2.2 Million Cars at Risk

A security gadget with a security hole
An aftermarket anti-theft device installed by dealerships to protect cars is itself carrying a security flaw, according to computer security researchers at the University of California San Diego. The vulnerability affects KARR and SWDS-branded devices and touches roughly 2.2 million vehicles, as reported by Fox News.
The devices are made and distributed by Southwest Dealer Services, which sells several product lines under the KARR name, including KARR Security, KARR Fusion, KARR BT and KARR S.W.A.T. Dealerships often install these units before a car is sold, tucking the hardware beneath the driver-side dashboard and sometimes slapping a KARR or SWDS sticker on the driver's window.
What the flaw actually lets someone do
Here's the mechanism, per the UC San Diego researchers' findings: someone standing within about five yards of a vulnerable vehicle can connect to the device over Bluetooth. Once connected, that person could lock or unlock the doors, silence the alarm, honk the horn, flash the headlights, or block the car from starting.
The researchers did not report that the vulnerability lets an attacker start the engine remotely or shut down a car that's already moving. Fox News, drawing on the same research, made a point of flagging that distinction directly: the Bluetooth exploit alone won't let a thief drive off in your car.
What it can do is quietly pop the locks. A thief who unlocks a car remotely doesn't need to smash a window or trip an alarm. From there, separate tools exist to program or clone a key, at which point the vehicle becomes a much easier target for actual theft, not just a break-in for whatever's sitting on the seat.
Why this matters even though it's not a full carjacking exploit
A device that can't start or steal the car outright is a narrower problem than, say, a flaw that hands over full remote control. Anyone defending the severity of this as overblown has a point: this is a break-in enabler, not a joyriding enabler.
But KARR and SWDS products are marketed as anti-theft systems, some with GPS tracking and ignition-disabling features, precisely to give car owners peace of mind. A security product that can be defeated by anyone standing near the vehicle with a Bluetooth-capable device undercuts the entire sales pitch. Owners who paid a dealership markup for extra protection are instead carrying hardware that adds a new attack surface.
What owners can actually do about it
Fox News's consumer advice piece, framed as a response to reader questions from a Cadillac XT5 owner and a Hyundai Tucson Limited Hybrid owner, makes clear there's no menu setting or dashboard code to check. KARR and SWDS aren't manufacturer features baked into the car's software. They're bolt-on hardware installed by the dealer, and the only way to know if your car has one is to look under the driver-side dash or check for the KARR or SWDS window sticker.
Buyers often don't know these systems were added, because the sale happens at the dealership level rather than through the automaker. Cadillac and Hyundai, as brands, don't install KARR devices as factory equipment. That means neither company's official support channels are likely to have answers, and owners have to go straight to Southwest Dealer Services or the dealership that installed the unit for a fix or a firmware update.
As of this writing, no recall notice or mandatory patch program tied to this vulnerability has been reported, and Southwest Dealer Services has not issued a public statement addressed in these findings. The open question for the roughly 2.2 million vehicle owners potentially affected: whether SWDS pushes a Bluetooth security patch, and whether dealerships that installed these systems reach out to notify customers, or whether owners are left to discover the flaw and hunt down the fix on their own.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.