Skip to main content

Nissan disables Leaf app following hacking scare

According to news reports, Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems. Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning. According to Helmes, “Fortunately, the Nissan Le
February 26, 2016 Read time: 2 mins
According to news reports, 838 Nissan has disabled its NissanConnect EV app after it was found that hackers could remotely control in-car systems.

Security researcher Troy Hunt discovered the vulnerability during a software workshop he was attending and has detailed his findings on his blog. In a test with fellow researcher Scott Helme, they found they were able to remotely turn on the car's heated seating, heated steering wheel, fans and air conditioning.

According to Helmes, “Fortunately, the Nissan Leaf doesn't have features like remote unlock or remote start, like some vehicles from other manufacturers do, because that would be a disaster with what's been uncovered. Still, a malicious actor could cause a great deal of problems for owners of the Nissan Leaf. Being able to remotely turn on the AC for a car might not seem like a problem, but this could put a significant drain on the battery over a period of time as the attacker can keep activating it.”

Paul Fletcher, cyber security evangelist at Alert Logic, comments, “The Nissan Leaf vulnerability is an issue that needs to be fixed by the manufacturer and while this vulnerability doesn’t have the same impact as the Jeep vulnerabilities documented last year, it’s an entry point into the controls of a vehicle and the potential for a more severe hack is now present."

Related Content

  • Benefits of traffic data sharing with app developers
    November 10, 2015
    Timothy Compston finds out if exchanging traffic and road condition data with private app developers makes sense for both drivers and road authorities. Much has been said about the potential benefits for authorities in sharing data with traffic and navigation app developers, and receiving ‘crowdsourced’ information in return – so how is it working in practice?
  • Traffic Group: ‘Daily commute may never be the same’
    May 22, 2020
    The pandemic has taught us that our ideas about travel might need a rethink - Wes Guckert suggests a few ways in which change is coming
  • Underinvestment in infrastructure threatens economic growth
    January 24, 2012
    The 2011 Urban Mobility Report from the Texas Transportation Institute highlights the dangers of continued underinvestment in transportation infrastructure but also offers some hope in terms of possible solutions
  • Inmarsat’s heavenly solution for connected vehicles
    October 11, 2016
    Inmarsat is at the ITS World Congress with some good news for vehicle manufacturers: Satellite communications can offer fast, over-the-air updating of connected and autonomous vehicles world-wide. Joel Schroeder, vice president of Inmarsat’s connected car program, said: “If the vehicle manufacturer discovers a problem or there is a security breach, then they need to fix it quickly. But the traditional way is to trace and contact all the owners of the affected vehicles and schedule visits to the dealer – an