Nissan pulls Leaf remote app after security flaw exposed
Nissan disabled its NissanConnect EV app for the Leaf after a researcher revealed that hackers could exploit a vulnerability to control certain car functions remotely.
Nissan suspended its NissanConnect EV app for the Leaf in February 2016 after a security researcher demonstrated that hackers could remotely access and control some of the car’s functions. The company said the app would remain offline until a fix was in place.
Australian security expert Troy Hunt revealed that the Leaf’s smartphone app could be exploited by anyone who knew the car’s vehicle identification number (VIN). This vulnerability allowed outsiders to turn on the climate control, start or stop battery charging, and access recent trip data without needing the owner’s login details.
Hunt published his findings on his website, showing that the app’s authentication system was weak enough that an attacker could control certain features simply by entering a valid VIN. While the flaw did not allow remote unlocking or starting of the vehicle, it still raised concerns about privacy and battery drain. Attackers could repeatedly activate the air conditioning or heater, which would reduce the car’s electric range.
Scope of the breach and Nissan’s response
Nissan confirmed the vulnerability and apologised to Leaf owners. The company said it disabled the app globally as a precaution while it worked on a secure update. The app had been available in several markets, including the UK, Europe, Japan and North America. Nissan did not specify how many vehicles were affected, but the Leaf was the world’s best-selling electric car at the time.
The company emphasised that no reports of malicious exploitation had been received before the vulnerability was made public. Nonetheless, the breach highlighted the risks associated with connected car features and the need for stronger security in automotive software. Nissan said it would restore the app once a more robust authentication system was in place.
Remote features and ongoing concerns
The NissanConnect EV app allowed Leaf owners to check battery status, control charging, set climate functions and review trip data from their smartphones. Although the app did not permit remote unlocking or driving, the exposure of trip histories and the ability to drain the battery raised questions about data privacy and practical security for electric vehicle owners.
The incident added to growing scrutiny of connected car systems, as more manufacturers rolled out similar apps. Security researchers and industry analysts called for stricter standards to protect vehicle data and prevent unauthorised access. Nissan said it would update customers when the revised app was ready.
For more on the Leaf’s technical evolution, see Nissan Leaf gains faster charging with 6.6kW onboard upgrade.
