Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

wiredwiredwiredResearchers from the University of California at San Diego and Oberlin College presented a technique at the Usenix Security Symposium on Wednesday capable of hijacking the autopilot of a Boeing 737 using a Wi-Fi-enabled device roughly the size of a quarter that costs less than $100 to build.wired
The attack, which the team dubbed "Bus Driver," exploits a specific externally accessible port on the aircraft — protected only by an unlocked hatch — that connects to an internal avionics network carrying data between the plane's Flight Management Computer and its Multipurpose Control Display Unit. The entire physical installation takes less than 60 seconds and requires no special tools.wired
Once implanted, the device sends electrical signals at a higher current than legitimate ones to override commands on the plane's internal bus. It can alter autopilot waypoints to redirect navigation, change variables like total aircraft weight and outside air temperature that determine takeoff performance, and spoof the pilot's display to hide those modifications. The researchers say such tampering could cause runway overruns, diversions into foreign airspace, or — in a worst case — catastrophic crashes.wired
"You can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan," said Stefan Savage, one of the UCSD professors who led the project.wired
Boeing, which was first notified of the vulnerability in 2020, said in a statement that it had reviewed its component designs and interfaces. "Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks," the company said. The researchers noted Boeing has not told them of any technical fix for the vulnerability.wired
Beau Woods, a cybersecurity consultant who has advised the Cybersecurity and Infrastructure Security Agency and served on Boeing's Industry Cyber Technical Council, called the paper "solid empirical evidence about some realistic scenarios for high-capability adversaries".wired
The researchers suggest immediate mitigations including plugging the vulnerable port with epoxy or removing the connector entirely. Longer-term, they recommend software-based detection of spoofed signals and cryptographic authentication between avionics components. The work, presented at the 35th Usenix Security Symposium in Baltimore, is the culmination of more than a decade of research.mlq+2