Philadelphia Live News

collapse
Home / Daily News Analysis / Researchers Built a Coin-Sized Device That Can Hack a Boeing 737’s Electronics

Researchers Built a Coin-Sized Device That Can Hack a Boeing 737’s Electronics

Aug 15, 2026  Twila Rosenbaum  9 views
Researchers Built a Coin-Sized Device That Can Hack a Boeing 737’s Electronics

While much of aviation cybersecurity focuses on network-based threats, researchers have shown that a physical attack on an airplane may require surprisingly little time or money. A team from the University of California San Diego and Oberlin College has developed a small, coin-sized device that can compromise the communications between two critical flight computers on Boeing 737 aircraft.

The prototype costs less than $100 to build and can be plugged into a maintenance port inside an electronics bay beneath the plane’s nose. That bay is accessible from the ground through an exterior hatch that is not locked and is routinely opened by maintenance workers and other airport personnel. According to the researchers, an attacker would need only 60 seconds to install the device, making it a realistic tool for someone with brief physical access to a parked aircraft.

The device is Wi-Fi enabled, which the researchers say could theoretically allow it to connect to the plane’s in-flight Wi-Fi and be controlled remotely from the internet. That means an attacker could plant the device on the ground and later take control from a remote location, expanding the attack surface far beyond the airport fence.

How the hack works

Once installed, the device interferes with the data link between the aircraft’s Flight Management Computer (FMC) and the Multipurpose Control Display Unit (MCDU) used by pilots. The FMC manages the flight plan and calculates performance data for takeoff, climb, cruise, and landing. Pilots use the MCDU to input routes, waypoints, and performance parameters. By inserting itself into this communication path, the device can secretly alter information on the pilot’s display while feeding false data to the autopilot and other systems.

In their paper, presented this week at the USENIX Security Symposium in Baltimore, the researchers described scenarios where a hacker could cause the autopilot to divert the aircraft into another country’s airspace or send it off-course. The device could also manipulate information about the plane’s weight, balance, and outside temperature, making a takeoff unsafe. In one test, the team showed that changing the outside temperature reading could cause the flight computers to calculate incorrect engine thrust settings, potentially leading to a runway overrun.

The researchers said they designed the attack to be stealthy. The device does not simply send random commands; it intercepts and modifies real data, so the pilot may not see obvious warnings or system failures. The MCDU might show a route that looks correct, while the autopilot follows a different path. This kind of deception is especially dangerous because pilots are trained to trust the FMC as the authoritative source for navigation and performance data.

Why the Boeing 737 is a target

The Boeing 737 is one of the most widely used commercial aircraft in the world, with about 8,000 currently in service, according to UC San Diego. The aircraft makes up roughly 25% of Delta’s fleet, 38% of American’s, 53% of United’s, and all of Southwest Airlines’ fleet. Its ubiquity makes it an attractive target for researchers studying aviation security threats, because a vulnerability found on the 737 could affect thousands of planes and millions of passengers.

The 737 family has been in production since the 1960s, and over the decades it has undergone many upgrades. Newer models, such as the 737 MAX, feature more advanced avionics and cybersecurity protections, but the physical architecture of the electronics bay and maintenance ports has remained largely consistent across the fleet. That means the research findings may apply to older and newer variants alike, although the researchers focused on the 737 Next Generation (NG) and 737 MAX platforms.

The physical access required for the attack is not as unlikely as it may seem. The electronics bay hatch is located under the nose of the aircraft, accessible from the tarmac. It is designed to be opened by maintenance workers, who use a standard key or latch. The hatch is not locked in the same way that a cockpit door is locked; it relies on the general security of the airport ramp area. However, airports employ many contract workers, baggage handlers, catering staff, and cleaners who have access to the ramp, and some airports have experienced security breaches involving unauthorized individuals reaching aircraft.

What the researchers demonstrated

The researchers built a working prototype of the device and tested it in a laboratory setting with actual 737 flight computers. They did not conduct tests on a live aircraft during flight or on a real passenger plane, but they used avionics components obtained from the secondary market, which are commonly used in engineering labs and flight simulators.

The device is based on a small microcontroller and a transceiver that can communicate over the databus used to connect the FMC and MCDU. The researchers reverse-engineered the communication protocol, which is based on ARINC 429, a standard aviation databus. ARINC 429 is a one-way, serial data bus that carries discrete values, such as altitude, airspeed, and navigation waypoints. Because the protocol was designed decades ago, it has no built-in encryption or authentication, making it vulnerable to tampering.

The researchers demonstrated several attack scenarios. In one, they altered the flight plan while the pilot was entering it into the MCDU, causing a waypoint to be moved by several nautical miles. In another, they changed the aircraft’s computed gross weight, which affected the takeoff speed calculations. They also manipulated the total air temperature, which is used by the FMC to calculate thrust and fuel flow. These attacks could go unnoticed until the aircraft behaves unexpectedly during a critical phase of flight.

“Our goal with this research is to alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous,” the researchers wrote in their paper. “We believe we have made a strong case that time-limited physical access (e.g., 60 seconds) represents a realistic goal for a motivated attacker and that the consequences of even such short access can be significant.”

Industry response and fixes

The researchers first alerted Boeing to their findings in 2020 and continued working with the company over the next several years. Still, they say they don’t know whether Boeing has done anything to fix the vulnerability. Their proposed fixes include tighter security around who can access planes on the ground, blocking the vulnerable port with epoxy, or removing it altogether. They also suggest that airlines could implement tamper-evident seals on maintenance panels, or employ more frequent inspections of the electronics bay.

Boeing did not immediately respond to a request for comment for this article. But the company earlier told Wired that it had reviewed the researchers’ findings and believes existing safeguards are enough to reduce any risks. “Our technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” Boeing told Wired.

The researchers admit that an attack of this type would require significant planning and engineering expertise, and that an attentive pilot could recover from most of the attacks they tested. They also note that the device alone is not enough to bring down a plane; it would need to be paired with knowledge of the specific aircraft’s avionics configuration and a clear objective. Nevertheless, they argue that even a partial loss of trust in flight data could have serious safety implications, especially in low-visibility operations or during automated approaches.

Broader implications for aviation security

The research adds to a growing body of evidence that the boundaries of aviation cybersecurity extend beyond the in-flight entertainment system or the airline’s booking network. Physical access to an aircraft’s maintenance ports has long been considered a lower risk than remote network attacks, because it requires a person to get close to the plane. But the researchers show that the cost and complexity of a physical attack are decreasing, and the potential consequences are high.

Aviation security experts have been calling for new standards for aircraft data buses, which were never designed with modern cybersecurity threats in mind. The Federal Aviation Administration (FAA) and the European Union Aviation Safety Agency (EASA) have issued guidance on cybersecurity for aircraft design, but much of the existing fleet is built on older technology that cannot easily be retrofitted. The researchers suggest that simply locking the electronics bay hatch or installing tamper-proof seals could be a low-cost deterrent, but it would not stop a determined attacker with inside knowledge.

The research also highlights the importance of human factors in aviation security. Pilots are trained to monitor systems and cross-check data, but they cannot observe every signal on the avionics bus. If an attacker can silently change a single waypoint or a temperature reading, the pilot may not notice until the aircraft begins to deviate from the expected path. Even then, the pilot might attribute the behavior to a malfunction rather than .

For passengers, the takeaway is not that flying is unsafe. Commercial aviation remains one of the safest modes of transportation, and physical access to aircraft is a scenario that security agencies and airlines continually work to control. But the researchers’ work demonstrates that cybersecurity is not just an internet problem. It is a physical safety problem that requires a holistic approach, combining secure engineering, operational procedures, and human vigilance.

The researchers themselves are not staying away from Boeing 737s. “All of the authors of this paper routinely travel on Boeing 737 aircraft and expect to continue doing so,” they wrote. They believe the commercial aviation system is resilient and that this class of attacks, while real, is manageable with appropriate safeguards. Their goal is to ensure that the industry adds those safeguards before a malicious actor takes advantage of the gap.


Source: Gizmodo News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy