This button is part of the KARR system. If it is installed in your car at the bottom of the dashboard, your car is likely vulnerable to the attack the researchers have discovered. Credit: David Baillot/University of California San Diego/Jacobs School of Engineering

At least 2.2 million cars on the road today are vulnerable to an attack that allows thieves to lock and unlock doors and immobilize vehicle engines remotely via a Bluetooth connection, computer scientists at the University of California San Diego have found.

Attackers can gain access to cars from as far as 5 yards (4.6 meters) away. Most of the vulnerable vehicles were bought at Honda, Toyota, Mazda, Ford and Jeep dealerships in Southern California from 2017 to today.

But because these vehicles are resold on the secondhand market, several hundred thousand vulnerable vehicles can also be found throughout the United States, Canada and even as far as Japan. Many vulnerable cars display a sticker with the word "KARR" or "SWDS" on the driver's-side window.

The vulnerability is due to a device controlled via a smartphone app that is typically installed by dealerships to manage vehicle inventory and prevent theft. The device, installed beneath the dashboard on the driver's side, connects the vehicle and app via Bluetooth.