Skip to content
Breaking:

UC San Diego Researchers Reveal Physical Hardware Exploit on Boeing 737 Systems

A minute of ground access allows a custom hardware implant to override legacy flight management buses on commercial aircraft.

By The Company Wire4 min read
Share
Boeing — UC San Diego Researchers Reveal Physical Hardware Exploit on Boeing 737 Systems
Boeing — UC San Diego Researchers Reveal Physical Hardware Exploit on Boeing 737 Systems. Photo: TechXplore.

A brief physical intrusion lasting under a minute could allow malicious actors to compromise critical flight systems on Boeing 737 commercial aircraft, according to new research from computer scientists at the University of California San Diego first reported by TechXplore. Presented at the USENIX Security Symposium in Baltimore, Maryland on Aug. 13, the study demonstrates that temporary physical access can be exploited to insert a custom electronic implant capable of hijacking internal communications between onboard computers.

The attack targets an unmonitored maintenance port inside the aircraft's Electronics and Equipment Bay, an unlocked compartment situated beneath the nose of the plane that is accessible directly from the ground. Former UC San Diego doctoral student Sam Crow, alongside computer science professors Aaron Schulman and Stefan Savage, demonstrated that plugging a custom hardware device into this port requires less than 60 seconds. An attacker could potentially execute the maneuver while an aircraft is parked at an airport gate or undergoing servicing inside a maintenance hangar.

Once installed, the device overrides the aircraft's ARINC 429 communication buses—a hardwired data networking standard introduced in 1977. Because the legacy buses transmit data using basic electrical current across two wires and resistors without modern message authentication protocols, the physical implant can suppress legitimate signals by driving higher electrical current. This grants the hardware device unauthorized command authority over data traveling between two vital onboard systems.

The hijacked systems include the flight management computer, which controls flight trajectories, landing approaches, and takeoff parameters, as well as the cockpit computer that feeds instrument data to pilots. Utilizing a proof-of-concept setup constructed with actual Boeing 737 parts and software, the research team successfully altered flight paths mid-flight and tampered with weight, balance, and temperature inputs essential for calculating safe takeoffs.

While flight crews could theoretically override unauthorized route or parameter adjustments, doing so relies entirely on pilots recognizing that instrument data has been corrupted. The researchers emphasized that executing such an attack requires significant advance engineering and tactical planning, making it a complex threat rather than an easily repeatable exploit.

The findings carry wide-reaching implications for commercial aviation, where the Boeing 737 remains an industry workhorse. Approximately 8,000 Boeing 737 jets are currently operating worldwide. The aircraft model comprises roughly 25% of Delta Air Lines' fleet, 38% of American Airlines' fleet, 53% of United Airlines' fleet, and 100% of Southwest Airlines' fleet.

The UC San Diego team initially disclosed the security flaw to Boeing in 2020 and subsequently validated their experimental results inside Boeing's testing facilities. Although the proof of concept specifically targeted the 737 architecture, the researchers noted that similar vulnerabilities likely extend across other commercial aircraft utilizing legacy bus systems.

"Our goal with this research is to alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous," said senior author Aaron Schulman, who noted that all of the study's authors regularly travel on Boeing 737 aircraft and plan to continue doing so.

Sources

  1. TechXplore

Company: Boeing

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.