Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Biometrics Institute addresses safety and security issues at CARTES
    November 5, 2014
    The use of biometric technology has spread rapidly in recent years, as it offers customers a simple and secure solution, whether they use it to identify themselves on smartphones, ATMs or bank branches. At CARTES SECURE CONNEXIONS 2014, international experts will discuss the most promising and innovative initiatives in this field.
  • TfL bans Uber from London following security breaches
    November 26, 2019

    Transport for London (TfL) has stripped Uber of its private hire operator's licence following security breaches which it says put passengers at risk.

    Uber slammed the decision but TfL says that a change in the ride-hailing giant’s systems allowed unauthorised drivers to upload photos to other driver accounts.

    This enabled the drivers to fake their identity and pick up passengers - in at least 14,000 trips.

  • A short guide to the shared mobility galaxy
    April 28, 2021
    This spring, a new book will be published with the mind-blowing title Shared Mobility Rocks: a Planner’s Guide to the Shared Mobility Galaxy. ITS International asks co-authors Friso Metz and Rebecca Karbaumer to share their golden rules
  • Westminster launches parking app
    October 31, 2014
    Westminster Council in London has launched the ParkRight app to enable drivers to find a parking space in central London. The Council has installed sensors on 3,000 roadside spaces in the city, and through the app motorists can identify streets with available bays to avoid driving around searching for a spot. Features include live ‘red, amber, green’ status for over 3000 spaces and locations of over 41,000 on and off-street parking spaces, with detailed information including number of spaces, operating h