Car alarm flaw lets attackers unlock and immobilize cars

A car alarm and remote start system fitted by dealers in vehicles around the world uses the same Bluetooth authentication key across devices, and CISA says an attacker within Bluetooth range can use that to unlock a car's doors or shut down its engine.

The advisory, ICSA-26-216-01, was published on 4 August 2026 and covers Acrisure's KARR BT and DR-100 anti-theft systems running firmware older than the 20 July 2026 release. The flaw is catalogued as CVE-2026-18411 under CWE-321, use of a hard-coded cryptographic key, and rated 8.1 (high) on CVSS 3.1.

How the flaw works

The point of pairing a Bluetooth device is that each one ends up with its own secret, so a command accepted by one car means nothing to the next. According to CISA, the KARR Security System and the SWDS dealer-installed automotive anti-theft systems instead use a shared Bluetooth authentication key across affected devices. Anyone who extracts that key from a single unit holds the key to every other unit that shares it. CISA says an attacker within Bluetooth range can then issue unauthorized commands to the vehicle, "potentially allowing unauthorized access to vehicle functions, including door unlocking and engine immobilization".

That last phrase is worth reading twice. Immobilization is the anti-theft feature doing exactly what it was built to do, triggered by somebody who should have no way to trigger it. The severity vector reflects the shape of the problem: the score is driven by integrity and availability impact with no confidentiality impact, and the attack vector is adjacent, meaning the attacker has to be in radio range rather than on the internet.

What you should do

Acrisure Protection Group released a firmware update on 20 July 2026 that addresses the vulnerability, and directs affected users to its published firmware update instructions. The practical difficulty is distribution. These are dealer-installed aftermarket systems rather than factory equipment, so there is no manufacturer recall channel pushing the fix to every affected vehicle. Owners and installing dealers have to seek it out. CISA reports no known public exploitation specifically targeting this vulnerability at this time.

The vulnerability was reported to CISA by Aaron Schulman, Jerry Yu, Yibo Wei, Sumanth Rao, Mohak Vaswani, Jefferson Chien, Christian Dameff and Nishant Bhaskar of the UC San Diego team. Full detail is in CISA's advisory ICSA-26-216-01. Hard-coded and shared secrets keep turning up in shipped products: IntelFusions recently covered CISA warning that attackers were abusing a built-in Cisco firewall password and a smart-building protocol flaw now under active attack.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions