Particle.news
Download on the App Store

Researchers Show 60‑Second Hardware Implant Can Override Boeing 737 Avionics

The validated proof-of-concept exposes decades-old unauthenticated ARINC 429 buses, prompting industry steps such as connector hardening, software detection, electrical isolation, protocol upgrades,

Overview

  • UC San Diego and Oberlin researchers presented a peer-reviewed proof-of-concept at the USENIX Security Symposium on Thursday that shows a small hardware implant can take over communications between two key Boeing 737 computers.
  • The device plugs into an unused maintenance port in the 737 Electronics and Equipment bay under the nose and can be installed in roughly 60 seconds with brief physical access to the aircraft.
  • The implant impersonates a participant on ARINC 429 hardwired data buses by driving electrical signals to override legitimate messages, allowing changes to flight‑plan and takeoff‑related values such as weight, balance and route.
  • The team disclosed the issue to Boeing in 2020, reproduced the attack in a Boeing lab, and said successful real-world exploitation would still need planning and engineering while pilots and current system layers can limit practical risk.
  • Researchers recommend short-term fixes—remove or block the unused connector, add software detection and increase electrical isolation—and longer-term fixes like authenticated avionics messages, a set of actions that will require industrywide coordination and supply-chain work.