
Image: Peter Haas · CC BY-SA 3.0 · via Wikimedia Commons
Researchers Reveal Rapid 60-Second Hardware Hack on Boeing 737 Avionics Systems
Security researchers demonstrated a physical implant attack compromising Boeing 737 NG and MAX avionics communications, requiring only about one minute of ground access.
The gist
A 60-second physical hack can disrupt Boeing 737 avionics data, exposing a serious aviation security vulnerability.
A team of security researchers from UC San Diego and Oberlin College unveiled a proof-of-concept hardware attack targeting Boeing 737 Next Generation and MAX aircraft avionics. Presented at the USENIX Security Symposium, the attack demonstrates how a device installed in about 60 seconds of physical access on the ground can interfere with critical data communication between avionics components. The researchers emphasize that while demonstrated on testbed hardware and software rather than in-flight aircraft, the vulnerability affects real operational models widely in service.
The attack centers on an unused maintenance connector located within the aircraft's Electronics and Equipment bay, positioned under the nose and accessible from the ground. The researchers estimate a five-step process to exploit this vulnerability: opening the access hatch in 15 seconds, installing the malicious device in about 30 seconds, and closing the hatch in 15 seconds, totaling approximately one minute of undetected physical intervention.
This implant targets the ARINC 429 data buses that relay information between the flight management computer and the multipurpose control display unit in the cockpit. By interfering with this conduit, the device can alter flight plan data and critical parameters related to weight, balance, and takeoff calculations. Notably, the attack suppresses some alerts on the pilot’s displays, potentially masking the tampering from flight crew.
UC San Diego professor Stefan Savage highlighted the severity of the findings, cautioning the aviation industry to proactively plan defenses against such attacks. The scope of impact is considerable as the research applies to Boeing 737 NG and MAX airplanes, which constitute over 95% of the active 737 fleet globally. The attack’s success depends on physical access, advanced technical knowledge, and prior planning.
The research group disclosed the vulnerability to Boeing in 2020 and later showcased the attack in Boeing’s own laboratories. Boeing reviewed the findings thoroughly and stated that their in-service protections within the aircraft’s design and operating context reduce the feasibility and risk of this kind of real-world assault significantly. Boeing emphasized confidence in multiple layers of security engineered into the airplane systems.
Researchers noted that pilot intervention could counteract unauthorized autopilot modifications by manual control, and some genuine information would remain viewable on other cockpit displays. To mitigate the risk, the team proposed several defenses including removing or permanently disabling the unused maintenance connector, implementing software that can detect suspicious activity, enhancing electrical isolation between avionics systems, and eventually adding authentication protocols to protect avionics data communications.
Given the evolution of avionics networks where digital communication is paramount, physical intervention vulnerabilities pose significant safety and security challenges. The research underlines that even brief, stealthy ground access can compromise flight-critical systems, urging operators and manufacturers to address these hardware-level attack vectors comprehensively.
This demonstration is a stark reminder of the need to rethink physical security in aviation maintenance areas, considering insider threats or malicious intrusions that could exploit overlooked access points. The findings will likely drive more rigorous assessments of avionics infrastructure and spur development of more resilient hardware and software protections.
In an aviation ecosystem growing increasingly reliant on interconnected avionics, this research represents a crucial call for renewed vigilance. The uncovered vulnerability highlights that comprehensive security must extend beyond software and networks to encompass physical access controls and hardware design choices.
Frequently asked questions
- How quickly can the hardware implant be installed on the Boeing 737?
- The researchers estimate that the implant can be installed in about 60 seconds total: 15 seconds to open the access hatch, 30 seconds to install the device, and 15 seconds to close the hatch.
- Which Boeing 737 models are affected by this avionics attack?
- The vulnerability applies to Boeing 737 Next Generation (NG) and MAX models, which account for over 95% of the active 737 fleet.
- What kind of data can the implant alter on the 737 avionics systems?
- The device can alter flight-plan information as well as weight, balance, and takeoff calculation values, while suppressing some indications on the pilot's display.
Read more
All Aviation Safety →
Defunct Cameroon Airlines Sues Boeing for $179M Over 1995 737-200 Crash
Boeing is suing to block a defunct airline's $179 million claim over a 1995 Cameroon Airlines 737 crash. The accident report blamed engine failure and pilot handling, while Boeing says the airline's purchase contract waived these claims decades ago.

IndiGo Passenger's Violent Outburst at Bhubaneswar Airport Raises Concerns Over Passenger Conduct
In general, I'm not a fan of posting videos of people having meltdowns at airports — "haha, look at this person having a really tough time, how funny." Yeah, to me it's not really funny. However, there's some video footage going viral over an airline passenger's behavior in India, and I think it makes for an interesting bigger picture discussion around how policies and norms differ globally when it comes to acceptable behavior at airports. Woman goes on rampage after IndiGo flight cancelation There's video footage going viral of an incident that happened at around 5:45PM on Thursday, August 13, 2026, at an IndiGo check-in counter at Bhubaneswar Airport (BBI), in India. According to reports, the woman pictured in the video was scheduled to travel on IndiGo flight 6E 7352 to Kolkata (CCU). It had been delayed by roughly three hours, before ultimately being canceled due to a technical fault. That's of course super frustrating. According to what was said in the video, her son was sick (it's not clear to what extent), and she was frustrated by the lack of timely information that she was given about the cancelation. Flight cancelations can of course be frustrating, but her response was beyond hostile — she started screaming, got up in the airport employee's face, slammed computer equipment, and more. It does look like after some significant backlash, a complaint has been filed against the passenger with the airport police station. The woman damaged a computer monitor, a keyboard, and a passport swiping machine, with damage being estimated to be around 49,000 INR (513 USD). IndiGo should seriously consider putting her on a no fly list. If this is how she reacts to something on the ground, imagine her reaction to an actual mid air emergency. She could become a danger to the crew & fellow passengers. Completely deranged! pic.twitter.com/v1y6smIUPG — Shilpa Godbole (@godbole_shilpa) August 14, 2026 It's interesting how airport behavior norms differ around the world It's not exactly insightful to point out that norms around behavior while traveling differ greatly depending on where in the world you are. If you compare airport behavior in Japan vs. the United States, you'd think you're on two different planets. There's no denying that as the aviation industry in India has grown massively, we've also seen more and more reports of poor passenger behavior. Honestly, we've seen a similar pattern in the United States over time. My point isn't to criticize one culture in comparison to another, but I think it's fascinating to watch this clip as an American, and in particular, the response. If a passenger behavior like this in the United States, they'd probably be tackled and tased by police. Like, this wouldn't be tolerated for a split second, and handcuffs would've been on the passenger in no time. Meanwhile here we see the passenger completely cross the line, and no one really seems to do anything. That then escalates when she goes from being verbally abusive to being physically abusive, throwing the computer equipment. Eventually some sort of police seem to get involved, but they just sort of seem to push her to the side. I don't want to be heartless, but I think this woman should've been restrained earlier. She could've just as easily become violent toward the airport employee she was towering over. For that matter, I think she should be placed on a no fly list. I mean, imagine if she engaged in this kind of behavior on an aircraft, without law enforcement, and without the ability for others to easily get away from her. What I also find noteworthy is looking at some of the social media responses to this. There are a surprising number of people coming out in her defense, saying things like "when a person is helpless what do you expect that person to do?" There are acceptable ways to express displeasure or anger. She is acting like an unhinged individual. — Shilpa Godbole (@godbole_shilpa) August 14, 2026 It's never acceptable to act this aggressively toward others, in my opinion. But in particular, it's not fair to blame a frontline customer service employee who has no control over the situation. These people didn't sign up to be abused by the public, and they don't deserve it. I understand every culture is different, but I really feel like regulators in India could do a bit more to establish what isn't acceptable behavior, and create punishments that hopefully deter people from working this way. We saw regulators in the United States increasingly fine passengers for poor behavior coming out of the pandemic, and I think that was fair and reasonable. Bottom line An IndiGo passenger became super aggressive after her flight was canceled. She climbed up on the baggage belt, yelled at the airport employee, and slammed computer equipment. It's totally understandable to be frustrated when things go wrong while traveling, though acting this way is never okay, in my opinion. What amazes me most is how everyone around her seems to tolerate this, and not actually take any action. Fortunately a complaint has now been filed against her, so hopefully she faces some punishment. If you ask me, this should land someone on the no fly list… What do you make of this IndiGo passenger abuse? PS: Let me remind everyone of OMAAT commenting guidelines . You're welcome to chime in here, but please be respectful, and don't rudely generalize cultures. If you see comments you take issue with, please hit the "Report" button.

Air India A320neo Flight Control Systems Briefly Failed Before 300-Foot Plunge Injuring 24
The flight control systems of an Air India Airbus A320neo narrowbody plane which suddenly plunged 300 feet while at cruising altitude, leaving 24 passengers and crew injured, went dark for several seconds, an internal report from the aircraft manufacturer has revealed. Air India flight AI-2379 from Phuket, Thailand to Delhi on August 4 was flying at a cruising altitude of around 34,000 feet when it unexpectedly dropped. Anyone and anything that wasn't strapped down was thrown into the air. Multiple passengers and crew were injured after they were slammed into the ceiling of the seven-year-old aircraft Around 20 passengers and four cabin crew members were injured in the incident, many of whom had to be transported to the hospital with head, neck, and spinal injuries. In a new internal report from Airbus which had been viewed by Reuters but not independently verified, it is claimed that the flight control system that controls the plane's elevators and ailerons suddenly became unavailable for around four seconds. During this brief period, the plane pitched up. The First Officer responded by pointing the nose of the plane down but there was no immediate correction due to the alleged loss of hydraulic systems. The document does not establish the cause of the incident and the events are still under investigation by India's Aircraft Accident Investigation Branch (AAIB) with support from the French Bureau d'Enquetes et d'Analyses (BEA). Late last year, Airbus issued an urgent safety alert for its range of best-selling A320 family single-aisle aircraft following an investigation into an incident aboard a JetBlue aircraft when the plane suddenly pitched down mid-flight without any input from the pilots. Engineers were able to establish that the unexpected pitch-down input came from a malfunctioning ELAC computer unit. The ELAC stands for Elevator & Aileron Computer, and it is designed to interpret the inputs the pilots are putting into the controls and then smoothly and correctly control the elevators and ailerons. Airbus believes that the ELAC was corrupted by intense solar radiation, although the issue only affected a software update known as L104. To fix the issue, airlines were ordered to restore all aircraft with the L104 software to the last version before this. In most cases, this required engineers to plug a Portable Data Loader with the older L103 software into the cockpit computer of affected planes and reinstall the tested software. Although there are around 11,500 Airbus A320 series aircraft in active commercial service around the world, only 6,000 of these had the L104 software installed. Earlier this week, it was revealed that the Captain of flight 2379 had failed a second drug test. As is standard practice following a serious aviation occurrence, all of the crew are subject to drug testing. The Captain's initial rapid test came back as 'non negative' so a more detailed test was ordered. Investigators are yet to confirm the results of this test, but sources claim it tes tested positive for cannabis. There is currently no suggestion that illegal banned had anything to do with the events that unfolded on flight 2379.

FAA Seeks Billions More to Fund CAP Automation Amid Growing Industry Competition
As competition for the FAA's common automation platform (CAP) contract heats up, the agency still lacks the funds required to develop the technology, which is envisioned to combine its En Route Automation Modernization (ERAM) and Standard Terminal Automation Replacement System (STARS) platforms. Thales becomes the latest company to pitch a CAP solution to the FAA. On Wednesday, it announced TopSky-America, a cloud-based, AI-powered platform that it said is tailored for the FAA to enhance information sharing, decision making, and situational awareness for air traffic controllers (ATCs). The idea is to reduce controller workload by combining data from ERAM, which manages high-altitude flights, and STARS, which coordinates arrivals and departures in towers and terminal route approach control (TRACON) facilities, in a single digital interface. STARS also provides sequencing and issues weather updates and conflict alerts. The CAP is billed as a core pillar of the Transportation Department's (DOT) Brand New Air Traffic Control System (BNATCS) effort. Without funding, though, it is unclear how the FAA plans to support the CAP's development and deployment. Congress last year allocated $12.5 billion toward BNATCS, while the DOT has requested a total of $31.5 billion to fund its more expensive components. The Modern Skies Coalition, led by the Aircraft Owners and Pilots Association (AOPA), in July called on Congress to allocate another $20 billion toward the effort. It estimated that the CAP alone would cost $10 billion. Transportation Secretary Sean Duffy has previously asked for the additional $20 billion but in recent months has signalled that the agency would settle for less. Duffy on Tuesday said the DOT "would love $20 [billion], but we'll take $10 [billion]." The secretary clarified that $10 billion would cover certain software upgrades planned under BNATCS. A "second $10 billion," he said, would be required for the "actual bricks and mortar" of new ATC facilities, such as TRACONs. Duffy did not mention the CAP in his remarks Monday, and the FAA's internal estimate of its cost is unclear. Thales said Thursday that it supports the "FAA's call for additional congressional funding." Competition Heats Up Thales described TopSky-America as an advanced ATC automation system "built specifically for the U.S. National Airspace System [NAS]." The platform is a version of the company's popular TopSky-ATC offering. But Thales emphasized that it is "customized for the unique requirements" of and designed "exclusively" for U.S. airspace. "These capabilities will deliver greater predictability for air carriers and the traveling public, improve operational performance, and help reduce workload on the controller workforce—while continuing to uphold the highest standards of safety," the company said in its announcement. TopSky-America is not the only CAP candidate. RTX's Collins Aerospace is pitching a version of its AutoTrac platform for the FAA contract, FlightGlobal reported in March. Collins was previously selected for BNATCS to provide hundreds of new ATC radars , while parent RTX is the FAA's prime STARS contractor. Leidos, which maintains the ERAM system, also has a CAP solution . The Air Current in April reported that Thales, Collins, Leidos, Australia's Frequentis, and Spain's Indra—the FAA's other BNATCS radar contractor—are the five companies shortlisted for the CAP contract. Thales' path to winning the contract could involve highlighting the success of its TopSky-ATC, which it estimates manages 40 percent of air traffic globally. The company in July announced agreements to modernize the air traffic management systems of Singapore and Mongolia. It also produces primary and secondary ATC surveillance radars and is developing capabilities for the management of uncrewed aircraft systems (UAS) traffic. Also working in the French company's favor is a commitment to design TopSky-America software upgrades in the U.S., a nod to the DOT's desire for domestic companies to lead the ATC modernization effort. "One of the focuses in modernization was to onshore production of critical infrastructure," FAA Administrator Bryan Bedford said Tuesday. "We have brought those jobs back to the United States, which is a key focus of [Secretary Duffy] and [President Donald Trump]." Thales has about 5,000 U.S. employees and said producing the platform domestically will create hundreds of new jobs. Ultimately, the contract award could come down to a battle among the shortlisted companies. Thales earlier this year lost out on the FAA's contract for Strategic Management of Airspace, Routes, and Trajectories (SMART)—an AI-powered, predictive air traffic management software —after being shortlisted for that award. Bedford said Tuesday that Thales, Palantir, and Air Space Intelligence (ASI), which ultimately won the contract, each created digital twins of the NAS for evaluation. Duffy described the exercise as a "competition" and said ASI produced the "best product, the best tool that we thought would help us best manage the airspace." "We want the best companies building our software," Duffy said. "And what's different is we're not just picking a contractor to work for us. We're actually going through a competition to see who actually can deliver on behalf of the FAA."
The Daily Touch & Go
The day's best aviation news in your inbox. Free, no spam.

