Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • February 27, 2013
    Internet-connected cars their functionality and safety challenges
    Internet-connected cars are poised to flood the market in the near future. Pete Goldin considers the functionality they offer, the technology they use and the challenge they represent in terms of driver safety. Many vehicles on the road today offer some sort of inter­net connectivity and experts agree that this capability will become a competi­tive differentiator in the automotive industry in the next few years. The era of the digital vehicle, it seems, has started. “We clearly see that cars in the near f
  • March 26, 2013
    Turning 4G mobile phones into multi-protocol transponders
    GeoToll, a new product that promises to turn the newest generation 4G mobile phones into a multi-protocol toll transponder is about to be launched in the US. OmniAir founder and president Tim McGuckin is leaving the interoperability standards cooperative to run GeoToll as its first chief executive officer. The device will be multi-protocol, so it will be usable on any toll system in North America, to the extent they can handle patent issues with licensing or open standards. GeoToll hopes to trial the devic
  • May 1, 2020
    What actually happens if we do #FreetheMIBs?
    Q-Free’s #FREEtheMIBs campaign highlights the use of manufacturer-specific data output, storage and communication protocols in traffic lights and ITS systems.
  • July 24, 2012
    In-vehicle safety standard released for consultation
    The new ISO 26262 standard for safety-related vehicle systems is now available for comment. MIRA's David Ward talks to ITS International about what the standard will mean for vehicle and road safety in the future. The publication on 8 July this year of ISO 26262 as a Draft International Standard (DIS) marks an important progression for the automotive - and, in time, the cooperative infrastructure - industries. A couple of years from now, automotive OEMs will be able to subscribe to a unifying standard for s