Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Spanish rail accident ‘could be the result of over-speed’
    July 26, 2013
    Investigations continue into the cause of the train crash approaching the Spanish city of Santiago de Compostela, but suggestions that the train was travelling too fast appear to be gaining weight. Officials say one of the train's drivers has been put under formal investigation. The president of railway firm Renfe, Julio Gomez Pomar, has said the train in the crash had no technical problems. "The train had passed an inspection that same morning. Those trains are inspected every 7,500km... Its maintenance r
  • Bosch’s Perfectly Keyless turns the smartphone into a car key
    November 15, 2017
    Bosch aims to end the ritual hunt for car keys with its Perfectly Keyless digital vehicle access system for vehicles equipped with suitable proximity sensors and control system. Drivers download an app onto their smartphone and connect the car to the app; the smartphone generates a one-off security key that fits the vehicle’s ‘digital lock’. The system then uses a wireless connection to the on-board sensors to measure how far away the smartphone is, and to identify the security key.
  • Will mobile apps kick-start mobility pricing?
    January 5, 2016
    Thomas Hallauer from Ptolemus believes trials of connected road charging services will show the pay per mile concept will go much further than previously thought. Drivers are progressively becoming directly connected to the transport infrastructure and while the methods are changing, the innovation is really in the models rather than the technology.
  • Westminster detects disabled parking bay abuse
    March 16, 2016
    Westminster trials scheme to detect non-qualifying motorists using disabled parking bays. The provision of disabled parking bays has become commonplace - but so has the abuse of these bays by able-bodied motorists. Now, London’s Westminster City Council is running a trial of technology that detects when a vehicle is illegally parked in a disabled bay.