Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

For more information on companies in this article

Related Content

  • Security loopholes found in BMW’s connected drive
    January 30, 2015
    On 30 January, security loopholes in BMW vehicles equipped with connected drive technologies were revealed. Believed to affect 2.2 million BMW vehicles worldwide, these flaws in the software allow thieves to unlock doors and track car data through a mobile phone without leaving a trace. The Federation Internationale de l'Automobile (FIA) has long advocated for secure, open networks for vehicle connectivity. Vehicle manufacturers have argued that only closed networks can be truly secure. In fact, the loop
  • Cities get road priorities right
    March 22, 2022
    Cities including Paris, Milan and London have all announced serious expansions to their bicycling infrastructure over the last few years. The era of active travel is here, finds Alan Dron
  • US DOTs introduce measures to stop wrong-way driving
    March 28, 2018
    Wrong-way driving (WWD) is a remarkably innocuous term for incidents that all too often cause some of the worst accidents that emergency services have to deal with. Several US states are now taking steps to minimise the problem, as Alan Dron finds out. You’re driving down a highway at night when you see approaching headlights. You initially assume they are merely those of an oncoming car on the opposite carriageway. It’s only when they are within 200 yards or so that you realise that the other driver is in
  • A more equitable approach to road charging: is the technology there yet?
    September 8, 2023
    Thinking around road user charging, distance-based payments, and even mileage rationing is ever-widening with new concepts and suggestions being aired and brought forward every other week. Yet, as Jorgen Petersen of Systra explains, there are already many solutions in place throughout the world which promote modal shift, reduce traffic and improve air quality…