At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, computer scientists at the University of California San Diego have found. Attackers can get access to cars from as far as five yards away. Most of the vulnerable vehicles were bought at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California from 2017 to today. But because these vehicles are resold on the second-hand market, several hundred thousand vulnerable vehicles can also be found throughout the United States, Canada and even as far as Japan. Many vulnerable cars display a sticker with the word “KARR” or “SWDS” on the driver’s-side window. The company manufacturing these devices, Acrisure, released a patch to fix the vulnerability on July 20, 2026. The fix requires downloading an app. “Many car owners don’t even know that their vehicle is vulnerable. So we wanted to make sure they were aware by publishing this study,” said Aaron Schulman, a professor in the UC San Diego Department of Computer Science and Engineering, and one of the study’s senior authors.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
