Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • April 27, 2015
    Rail signalling system ‘could be liable to hacking’
    A new rail signalling system to be installed across the UK could be liable to hacking, a government adviser has warned. Professor David Stupples told the BBC that the European Rail Traffic Management system (ERTMS) could be exposed to malicious software, or malware, and used to cause an accident perhaps telling the system the train is slowing when down when it is speeding up. "However, he said governments aren't complacent."Certain ministers know this is absolutely possible and they are worried about
  • January 26, 2012
    Improving driver information, making in-vehicle systems a reality
    Scott J. McCormick, president of the Connected Vehicle Trade Association, considers what we have to do next to make the more widespread deployment of automotive telematics a reality
  • February 18, 2013
    Oxford University develops self-driving car
    Oxford University scientists have developed a self-driving car system that can be installed in existing cars and can cope with snow, rain and other weather conditions. Developed by a team led by Professor Paul Newman at Oxford University, the new system has been installed in a Nissan Leaf electric car and tested on private roads around the university. The car will halt for pedestrians, and could take over the tedious parts of driving such as negotiating traffic jams or regular commutes. The car alerts the
  • April 1, 2019
    Swarco: ‘Everyone’s running after buzzwords’
    The ITS world finds itself in a time of great change. Swarco’s Michael Schuch talks to Adam Hill about connectivity, the increasing importance of the end user – and why you shouldn’t leave your core business behind