Tiny Device Can Hijack Boeing 737 Autopilot System
A team of researchers at the University of California San Diego and Oberlin College demonstrated that a small, coin-sized device can be plugged into an externally accessible port on a Boeing 737 to override its autopilot system. The attack allows hackers to feed false data to pilots without detection.
The vulnerability centers around the data bus connecting the Flight Management Computer (FMC) to the Multipurpose Control Display Unit (MCDU). A diagnostic port, protected only by a dust cap, can be exploited with a device costing under $100. This allows hackers to intercept, alter, and spoof commands between the FMC and MCDU.
The researchers identified this vulnerability after years of work and shared their findings with Boeing six years ago. However, they claim that no remediation has been implemented, despite multiple layers of protection existing within the aircraft's system design and operating environment.