Security researchers are warning that around 2.2 million vehicles in California could be exposed to a Bluetooth-based attack tied to dealer-installed protection systems. The issue centers on KARR and SWDS products, which are fitted by dealerships rather than built directly into a carmaker’s standard platform.

According to the findings, the flaw could let an attacker remotely unlock vehicle doors and also prevent a car from starting. That combination raises concerns because it affects both access to the vehicle and a core function needed to drive it.

The warning is notable because the vulnerability is linked to aftermarket-style security hardware installed at the dealership level. That means the risk may cut across multiple vehicle brands and models if they use the same KARR or SWDS systems, instead of being limited to a single automaker.

Experts are highlighting the scale of the exposure in California, where the number of potentially affected cars is estimated in the millions. For drivers, the report shifts attention beyond factory software and toward dealer-added technology that may introduce its own cybersecurity weaknesses.