Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • August 8, 2018
    Regulation time-lag will hit driverless technology hard says leading consultancy BDO
    The legislation surrounding driverless cars is lagging so far behind the technology involved that the industry is unlikely to see a regulatory framework in place any time soon says leading international business, finance and taxation consultancy BDO. And IEEE, "the world’s largest technical professional organisation dedicated to advancing technology for the benefit of humanity" can only see problems ahead as the politicians fall further and further behind. BDO has been looking at a report from www.Spectr
  • December 19, 2024
    Great (shared) mobility expectations
    An invitation to attend Movmi's Shared Mobility Fall Masterclass changed the way Adam Hill looked at micromobility - in particular his own attitude to risk
  • December 5, 2018
    Safety issues fuel interest at PIARC’s tunnel conference in Lyon
    1999’s fatal Mont Blanc fire means safety is a constant concern for tunnel operators. Alternative fuels and automated vehicles were also high on the agenda at PIARC’s first conference on the issue. David Arminas reports from Lyon – and walks the Croix-Rousse tunnel More than ever, tunnel management must be done in a holistic fashion. That was the message from André Broto, president of the World Road Associa-tion (PIARC) as he kicked off PIARC’s first International Conference on Tunnel Operations and Safe
  • November 28, 2013
    NavFusion provides map updates via a smart phone app
    A new app that connects a vehicle’s systems to the internet opens up a range of possibilities as Jon Masters discovers. Sometimes the most straightforward or simple of ideas can be the most significant. So it seems with the latest development from Hungarian navigation software supplier NNG. The company’s software features in-vehicle infotainment systems and has launched NavFusion – which connects a vehicles’ sat nav programs to smartphones. NavFusion is being incorporated into NNG’s iGO navigation s