— Millions of vehicles equipped with dealer-installed aftermarket anti-theft systems may actually be more vulnerable to theft because of a Bluetooth security flaw discovered by researchers at the University of California San Diego. The researchers estimate that at least 2.2 million vehicles sold since 2017, primarily through Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California, are affected. Because many of these vehicles have entered the used car market, vulnerable vehicles are now spread across the United States, Canada, and other countries.

The vulnerability affects KARR and SWDS systems installed by dealerships as inventory management and optional anti-theft devices. Researchers found that every device relied on the same encryption key, allowing attackers within Bluetooth range to unlock vehicle doors and disable or enable engine immobilization functions. While the flaw alone does not let thieves start a vehicle, it can eliminate one of the biggest barriers to theft by providing access to the interior, where other commonly available automotive tools could be used to complete the theft.

For insurance claims professionals, the findings could influence theft investigations involving vehicles equipped with aftermarket dealer-installed security systems. Adjusters may encounter claims where owners believed their vehicles had enhanced theft protection, only to learn the installed system created an unexpected vulnerability. Knowing whether a vehicle carried one of these systems may become relevant when evaluating theft circumstances, reviewing police reports, or investigating recovery timelines.

The issue also presents potential subrogation considerations. Depending on the facts of an individual claim, insurers may evaluate whether liability extends beyond the vehicle owner to dealerships, installers, device manufacturers, or other parties involved in the installation and security of the aftermarket system. The researchers note that the devices remain active even when customers decline the paid security service, potentially expanding the population of affected vehicles.

Acrisure, the manufacturer of the KARR-SWDS devices, released a firmware update on July 20, 2026. Vehicle owners must install the update through the KARR mobile app. The researchers recommend stronger authentication requirements for future Bluetooth-enabled vehicle security products, including requiring physical interaction inside the vehicle before pairing a new smartphone.