Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • January 30, 2012
    e-Call emergency service doesn't go far enough
    eCall misses the point and is only a tacit acknowledgement that the road safety issue has not yet been adequately addressed, according to FEMA's Aline Delhaye. According to the Federation of European Motorcyclists' Associations (FEMA), the European Commission's (EC's) ambitions for eCall implementation are premature and fail to take account of all road users' needs or of technological progress elsewhere.
  • December 7, 2020
    Saving the world, one parking space at a time
    Donald Shoup, professor of urban planning at University of California, Los Angeles (UCLA), tells Adam Hill about why parking is too cheap – and how Monopoly could seriously raise its game
  • May 27, 2014
    Activu and Mitsubishi give New Jersey controllers the big picture
    Mitsubishi and Activu team up to help New Jersey emergency centre with real-time situational awareness. Sandy was the largest Atlantic hurricane in recorded history, with winds spanning an area of 1,100 miles and damages estimated at $68 billion. It killed at least 286 people in seven countries, from Jamaica to the Jersey Shore. But tropical storms are not the only challenge for emergency operations up and down the East Coast.
  • January 25, 2012
    Connected vehicle technology the solution to safety?
    A series of 'driver clinics' is under way across five states, as vehicle manufacturers and the US Government pin their hopes on connected vehicles becoming the next big advance in road safety. Pete Goldin reports. What would a car say if it could talk? Its first words might be: "Here I am". Many vehicles are communicating that very message to each other right now. Admittedly, this is in controlled environments of US Department of Transportation (USDoT) tests, but within the next few years 'connected vehicle