Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Robotic Research: harnessing AV potential
    June 10, 2021
    Robotic Research is leading in AV R&D, from work with the US Army to enabling the first automated BRT line in North America: Gordon Feller assesses what the company is doing
  • The great pay divide
    April 2, 2014
    Public acceptance is crucial for the acceptance of managed and express lanes as Jon Masters discovers. Lists of proposed highway expansion projects introducing variably priced toll lanes continue to lengthen. Managed lanes, or express lanes to some, are gaining support as a politically favourable way of adding capacity and reducing acute congestion on principal highways. In Florida, for example, the managed lanes on the 95 Express are claimed to have significantly increased average peak-time speeds on tolle
  • EU steps up efforts to tackle cyber threats
    July 7, 2016
    The Commission has launched a new public-private partnership with the non-profit European Cyber Security Organisation (ECSO) on cyber-security that is expected to trigger US$2 billion (€1.8 billion) of investment by 2020. This is part of a series of new initiatives to better equip Europe against cyber-attacks and to strengthen the competitiveness of its cyber-security sector. The EU plans to invest US$500 million (€450 million) under its research and innovation (R&I) programme Horizon 2020, with the rema
  • Urban tunnel replaces viaduct, improves safety
    October 10, 2012
    Earthquake sensors, automatic barriers and real time monitoring systems are all part of a scheme to make a major Seattle traffic artery safer, by taking it underground. Huw Williams reports. Seattle’s metropolitan area of 3.5 million people, like much of the western seaboard of the United States, lies in an earthquake zone. In Seattle’s case, the city and its hinterland sit atop a complex network of interrelated active geological faults capable of severe seismic activity and posing complex considerations fo