HomeSecurityVulnerability in Nissan Leaf allows full control of the car

Nissan Leaf vulnerability allows full control of the car

A team of researchers from PCAutomotive revealed to Cyber ​​Security News that attackers could gain full access to second-generation Nissan Leaf electric vehicles (2020 model) through a vulnerability in the infotainment system, thus providing unprecedented remote control over critical vehicle functions

See also: New low-cost Nissan Micra EV expected this year

The exploit chain, which was demonstrated at Black Hat Asia 2025, allows malicious users to control doors, mirrors, steering, and security systems from anywhere with a mobile connection.

Nissan Leaf vulnerability

The attack begins by exploiting a stack buffer overflow (CVE-2025-32059) in the Nissan Leaf's Bluetooth Hands-Free Profile (HFP).

Attackers can trigger this vulnerability by sending malicious audio data to the vehicle's infotainment system, requiring only temporary proximity to the target (e.g., in parking areas or traffic locations).

See also: Nissan: Recall of models using Takata airbags

After initial access is obtained:

  • Persistence Mechanism: The compromised system connects to servers controlled by the attackers via the Leaf's built-in mobile modem, ensuring its survival after reboots.
  • Firewall Exploit: Attackers disable critical iptables rules, allowing unrestricted external communication.
  • CAN Bus Seizure: Researchers bypass Nissan's gate filters by exploiting an overflow in the Renesas RH850 microcontroller, gaining rights to transmit raw CAN messages.
Nissan Leaf vulnerability allows full control of the car
Nissan Leaf vulnerability allows full control of the car

For Leaf owners:

  • Disable Bluetooth when you are parked in public areas.
  • Contact service centers for urgent ECU updates (Report NHTSA #2025-LEAF-004).
  • Monitor for unusual system behavior (e.g., mirror movements, unexpected warnings).

See also: Nissan North America: Data breach affects 53,000 employees

As vehicles become increasingly connected, this exploit is a stark reminder of the physical risks associated with digital vulnerabilities . Regulators are now proposing mandatory penetration testing standards, similar to aviation security protocols

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS