SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.
USACybersecurityDiagnostics & Service

CISA flags a shared Bluetooth key in dealer-fitted car alarms that can immobilize engines

An advisory published August 4 said KARR anti-theft systems used one Bluetooth authentication key across devices, letting anyone within radio range open the doors and stop the engine.

The US Cybersecurity and Infrastructure Security Agency published an advisory on August 4 covering the KARR Security System and SWDS anti-theft systems, aftermarket equipment installed by dealers rather than fitted by the manufacturer. The agency said the devices used a Bluetooth authentication key shared across units, allowing an attacker within Bluetooth range to issue unauthorized commands to a vehicle, including releasing the door locks and immobilizing the engine.

The flaw is tracked as CVE-2026-18411 and classified under CWE-321, use of a hard-coded cryptographic key. CISA scored it 8.1 on version 3.1 of the common vulnerability scoring system and 7.2 on version 4.0, both in the high band. The affected products are Acrisure KARR BT firmware and Acrisure DR-100 firmware in versions earlier than a July 20, 2026 release. The advisory listed the vendor as based in the United States, deployment as worldwide, and the sector as transportation systems.

Acrisure Protection Group released firmware addressing the vulnerability on July 20, fifteen days before the advisory appeared, and CISA pointed owners to the KARR product site for instructions. The vulnerability was reported to the agency by eight researchers at the University of California, San Diego.

The advisory gave no figure for how many vehicles carry an affected module, and described no mechanism by which an owner would learn that a dealer-installed accessory needed reflashing.

Source: CISA, August 4, 2026.

Why it mattersAccessories fitted at the dealership sit outside the software-update regime that UN R156 imposes on the vehicle itself, so a fix can ship without any route by which the affected cars find out they need it.

Source: CISA ICS advisory ICSA-26-216-01

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.