The new boundary is installed after the vehicle leaves engineering
UC San Diego researchers disclosed vulnerabilities in KARR and SWDS aftermarket alarm systems installed in at least 2.2 million vehicles. The systems use Bluetooth to control functions such as locking, alarms and immobilisation, and the researchers found a shared security key across devices. The vendor released a firmware update in July 2026.
The architectural lesson is broader than one product. An aftermarket module can be physically spliced into vehicle wiring, gain access to functions that owners assume belong to the OEM security architecture, and remain installed even when the buyer did not actively choose the service. That creates a trust path introduced by the retail and service chain rather than by the vehicle development organisation.
UN Regulation No. 155 treats cybersecurity as a lifecycle risk-management problem. A privileged aftermarket device therefore cannot be viewed only as an accessory. If it can influence security-relevant vehicle behaviour, its authentication, update path, inventory status and incident response become part of the product risk model.
This path shows how an aftermarket device can inherit vehicle-control authority through a backend whose trust assumptions were created outside the OEM engineering baseline.
Can the vehicle owner or OEM identify, authenticate, constrain and update every privileged aftermarket device?
Openness and repairability still need bounded authority
The answer is not to make vehicles impossible to modify. Aftermarket services, diagnostics and repair ecosystems create legitimate value. The control objective is to prevent physical access or commercial installation from automatically becoming digital trust.
A defensible integration model needs a constrained gateway policy, strong per-device credentials, explicit enrolment, auditable update mechanisms and a way to discover which vehicles actually contain the component. The hardest containment problem in the KARR case is not only firmware. It is knowing which vehicles carry the device and ensuring owners receive the fix.
For OEMs and fleets, the practical question is therefore inventory plus authority: which non-OEM components can issue commands, which functions can they influence, and who owns their security lifecycle after resale, refurbishment or a change of vehicle ownership?
- Inventory dealer-installed devices by vehicle/VIN where possible.
- Require unique credentials and explicit pairing for privileged functions.
- Constrain aftermarket authority at the vehicle gateway.
- Define patch ownership and owner notification before deployment.
- Include aftermarket components in incident and recall decision paths.
