Millions of cars could be tracked and unlocked by a hidden security flaw


A car alarm vendor’s coding mistake has left millions of vehicles vulnerable to theft and location tracking. Thanks to the way dealers sell car alarms, many affected drivers don’t even know they have one installed.

The device is the KARR Security System, a Bluetooth-enabled aftermarket alarm built by Acrisure Protection Group. It’s installed by dealers, primarily at Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California.

Aftermarket car alarms are a strange corner of the auto industry. Dealers install them in your car before you ever see the vehicle, then try to sell you the subscription afterward. Say no and the hardware still stays put. According to researchers at the University of California San Diego, KARR systems are installed in about 2.2 million American vehicles, and around half of owners don’t even know they’re there.

Read more…
Source:  MalwareBytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Hacking cars: cybersecurity regulations needed for new vehicles

    July 16, 2017

    Imagine driving your pickup truck off-road and suddenly having your airbags and seat belts malfunction because of an object striking the undercarriage. That causes a software error in your smart vehicle, causing the computer to incorrectly turn off critical equipment that protects you. Sounds far fetched? It shouldn’t. It’s part of a recall notice that affected more than 200,000 ...

  • Autonomous car cyber security consortium awarded funding

    April 11, 2017

    An autonomous car cyber security group will receive government funding as part of a plan to make the UK a hub for the development of self-driving cars, it has been announced. The 5*Stars consortium, which incorporates HORIBA MIRA, Ricardo, Thatcham Research, Roke and Axillium Research, will get grants to develop defences against cyber attacks on autonomous ...

  • Senators reintroduce a bill to improve cybersecurity in cars

    March 23, 2017

    Senators Ed Markey of Massachusetts and Richard Blumenthal of Connecticut have reintroduced the Security and Privacy in Your Car (SPY Car) Act of 2017. They first introduced the bill, along with a similar bill for aircraft, during the last session. The SPY Car Act places the onus for automotive cybersecurity and privacy standards on the shoulders ...

  • Popular hacker warkit Metasploit now hacks hardware and cars

    February 3, 2017

    Popular offensive hacking toolkit Metasploit now works on hardware, including cars, after a major update to the 13-year old platform. The free-or-paid modular hacking machine now sports plenty of CVE-specific exploitation components that security professionals have long-used for penetration tests and research. An update to the Hardware Bridge API means the platform will now work on variety ...

  • Court Documents Reveal How Feds Spied On Connected Cars For 15 Years

    January 16, 2017

    It’s not always necessary to break into your computer or smartphone to spy on you. Today all are day-to-day devices are becoming more connected to networks than ever to add convenience and ease to daily activities. But here’s what we forget: These connected devices can be turned against us because we are giving companies, hackers, and ...