Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • September 15, 2016
    Deadlines approach for Europe’s automatic crash alert system
    The EU-co-funded I_ HeERO (Infrastructure_ Harmonised eCall European Pilot) project is working to ensure the readiness of national networks of call centres - known as public safety answering posts (PSAPs) - to deal with automated crash alerts arriving via the continent-wide 112 emergency phone number. Following on from its HeERO and HeERO2 pre-deployment predecessors, which enjoyed €16m (US$17.76m) in EU funding, the new initiative runs from 1 January 2015 to 31 December 2017. It has €30.9 million (US$34.
  • March 4, 2024
    Let’s explore Phoenix: Getting transit right in the hottest city in the US
    Ahead of ITS America's Conference & Expo in Phoenix, ITS International asked Transit Unplugged's Paul Comfort (with Tris Hussey) to offer some thoughts on urban mobility in this part of Arizona
  • February 2, 2012
    Governments must look beyond short-term spending of public funds
    Phil Pettitt, Chief Executive of innovITS, the UK's ITS Centre of Excellence, argues that governments need to look beyond the short-term when looking to pump-prime economic recovery with public funds. It seems, in the current economic climate, that a 'good' day is one in which no company is announcing job cuts or going into administration. Consumer demand is down and businesses are retrenching, cutting costs and fretting over the consequences of shrinking opportunities and order books. It has not been this
  • January 30, 2015
    Security loopholes found in BMW’s connected drive
    On 30 January, security loopholes in BMW vehicles equipped with connected drive technologies were revealed. Believed to affect 2.2 million BMW vehicles worldwide, these flaws in the software allow thieves to unlock doors and track car data through a mobile phone without leaving a trace. The Federation Internationale de l'Automobile (FIA) has long advocated for secure, open networks for vehicle connectivity. Vehicle manufacturers have argued that only closed networks can be truly secure. In fact, the loop