Bluetooth Vulnerability Puts 2.2 Million Cars at Risk of Hijacking in California
Researchers at the University of California San Diego have discovered a vulnerability in Bluetooth-based security systems installed in 2.2 million vehicles, primarily in California. The security systems, manufactured by Acrisure and installed by car dealers, are susceptible to remote control via Bluetooth. This flaw allows potential attackers to unlock vehicles and control certain functions. The affected vehicles, purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, have the 'KARR-SWDS' label. The vulnerability stems from the use of a common secure key across all devices, making them vulnerable once the key is cracked. Despite the availability of a firmware update, the issue remains concerning due to the complexity of removing the devices.