Nicosia, CY
17°C
2.6 m/s
82%

The Boeing 737 Autopilot Can Be Hacked with a Coin-Sized Device

14.08.2026 / 14:47
News Category

The aircraft can be attacked not through the internet and not via the pilot’s onboard computer. Researchers have found a much more unusual route: a tiny electronic device physically installed on board can interfere with data exchange between aviation systems. In certain scenarios, this makes it possible to alter commands sent to the autopilot while simultaneously falsifying the information displayed to the crew.

The study was presented by a team of specialists from the University of California, San Diego, and Oberlin College. The work was the result of more than a decade of research into the security of aviation electronics. For their experiments, the researchers assembled a special test rig from real Boeing 737 avionics components purchased on the secondary market.

The most dangerous thing here is not the size of the device

At first glance, the story sounds like science fiction: a device roughly the size of a coin is connected to the aircraft and then gains the ability to interfere with its electronic systems.

But the attack principle is quite down-to-earth. The researchers found that certain internal 737 data buses have physical ports intended for maintenance and diagnostics. One of these interfaces is connected to systems involved in the operation of the Flight Management Computer — the computing system responsible, among other things, for route management — and the flight control display.

The key problem lies in the architecture: the aircraft’s internal systems must constantly exchange data with one another, and not every such channel was originally designed with a scenario in mind where an attacker physically connects a specially created device to it.

The researchers called the technique they developed Bus Driver. Broadly speaking, it allows the device not merely to listen to data on the bus, but to interfere with its transmission and replace legitimate commands. The attacker does not necessarily have to physically cut wires or install a complex intermediary module: gaining access to a suitable interface is enough.

What exactly can be changed

The most serious part of the experiment is related to navigation.

The researchers showed that with this kind of access, it is possible to influence the data exchanged by systems connected to route management. In particular, it may be possible to alter the programmed waypoints, potentially causing the autopilot to begin following modified instructions.

But another possibility is even more interesting: falsifying the information seen by the crew.

In the experiment, the researchers were able to affect not only data inside the aviation network, but also information sent to the control interface. In theory, this could create a situation in which the aircraft’s internal system receives altered parameters while the pilot sees data on the display that appears normal.

This is fundamentally different from an ordinary malfunction.

When equipment fails, the system generally attempts to inform the crew that there is a problem. In an attack, however, the goal is for the system itself to keep working while some of the information within it is deliberately distorted.

The most dangerous scenario is deceiving the pilot

Imagine a situation in which one of the aircraft’s parameters has been artificially changed.

If the crew sees an obvious error, such as contradictory readings, the pilots can switch to backup instruments, disable the automated systems and take control themselves.

But if the malicious interference looks like ordinary data, detecting the problem becomes much more difficult.

The researchers examined scenarios involving changes to parameters that matter for calculations and navigation, including data on the aircraft’s weight and the outside temperature. Incorrect values could potentially affect calculations performed by the aviation systems.

That is why the main threat here is not simply the ability to “turn the aircraft”.

Far more dangerous is the possibility of making the automation take incorrect decisions while simultaneously giving the crew the impression that everything is operating normally.

And Wi-Fi introduces another level of risk

The device itself must be physically installed on the aircraft. This is a crucial limitation.

The researchers did not demonstrate a scenario in which an unknown attacker simply sits at home and connects over the internet to a random Boeing 737.

First, physical access to the aircraft is required to install the implant. That is why the attack primarily falls into the category of threats posed by someone who has access to the aircraft on the ground: a technical-service employee, maintenance worker or another person able to be near the aircraft at the right moment.

However, once the device has been installed, the situation changes.

The researchers’ prototype is equipped with a wireless interface. Therefore, in a certain scenario, it could use the onboard Wi-Fi network to communicate with an external operator. This creates the potential for remotely interacting with an already installed device during flight.

This is precisely what makes the study particularly troubling: physical access is required for the initial intrusion, but subsequent control of the implant could potentially be carried out remotely.

At the same time, it is important not to exaggerate the findings. The researchers did not prove that any passenger could connect to an aircraft’s Wi-Fi and take control of a Boeing. Such a scenario would require the prior installation of specialized equipment and the use of a specific feature of the aircraft’s architecture.

Why pilots are not helpless after all

Despite the striking headline, the study does not mean that the Boeing 737 has become a “flying computer with no protection”.

The crew still has ways to detect and compensate for such interference. In particular, manually flying the aircraft makes it possible to disconnect from reliance on the autopilot, while some information is available through independent systems and instruments.

The researchers themselves note that an attentive crew would be able to notice inconsistencies and regain control in many of the scenarios they examined. The problem arises when the changes are small enough, or carefully chosen enough, not to trigger obvious concern.

In other words, this is not a “button that instantly brings down an aircraft”, but a far more complex threat — covert interference in the trusted information environment of the crew.

Boeing had known about the research for several years

One particularly important point is that this was not a vulnerability suddenly discovered yesterday, with the manufacturer learning about it from the media.

The researchers informed Boeing of their findings as early as 2020 and continued working with the company as the research progressed. They also demonstrated elements of the attack in Boeing’s laboratory environment. The company conducted its own review of the aircraft’s design, components and interfaces in connection with the findings.

In addition, the researchers did not publicly disclose some technical details that could have made it easier to reproduce the attack directly.

How could this have been overlooked?

The answer lies in a fundamental security principle of older aviation electronics.

A modern aircraft is not a single computer. It is a vast distributed system made up of numerous specialized computers, sensors, displays and data-exchange channels.

This architecture was created primarily with reliability, fault tolerance and predictability in mind, rather than the modern concept of cybersecurity, in which every device and every message must undergo cryptographic authentication.

If a system has assumed for decades that equipment physically connected to an internal bus is trusted, the emergence of a miniature device capable of imitating a legitimate network participant completely changes the threat model.

This is what the researchers consider the main conclusion of their work.

What they propose doing

The simplest solution is to remove the potentially dangerous interface or physically block access to it.

A more fundamental approach would involve changing the architecture of aviation electronics itself: strengthening electrical isolation between systems, detecting anomalous signals and, ultimately, using cryptographic authentication for commands within onboard networks.

This is far more difficult than closing off a single connector: aviation equipment undergoes certification and is designed to operate for decades. Therefore, any change to onboard electronics requires substantial engineering and regulatory work.

The main conclusion

The story of a “coin that hacks a Boeing” sounds like another cyberpunk plot, but the study demonstrates a very real engineering problem.

An aircraft does not have to be connected to the internet for its computer systems to be attacked. Sometimes a few seconds of physical access to the right interface are enough.

And that is the most important result of the research by UC San Diego and Oberlin College. The future threat to aviation may come not only from a remote hacker, but also from a tiny device that no one notices after maintenance.

At the same time, passengers should not interpret the study as proof that flying on a Boeing 737 has become unsafe: the demonstrated attack requires physical access, specialized equipment and a deep understanding of the aircraft’s specific architecture. Moreover, the researchers disclosed the issue to the manufacturer in advance, and Boeing conducted its own review.

But the idea itself changes the rules of the game: in an era of miniature electronics, even an aviation system that is physically isolated must be regarded as a potential cyber target.

Comments (0)