Physical Access: Researchers Demonstrate Novel Boeing 737 Autopilot Hack via External Port
Academic researchers have unveiled a groundbreaking method to compromise a **Boeing 737**'s autopilot and flight calculations through a small, inexpensive, physically installed device. This technique, presented at the **Usenix Cybersecurity Conference**, highlights a significant blind spot in aviation security, challenging the long-held belief in the inaccessibility of aircraft systems to hackers.
While critical digital systems in cars, medical devices, and infrastructure have proven vulnerable to cyberattacks, the computer systems of airplanes have largely remained insulated. However, a team of researchers from the **University of California at San Diego** and **Oberlin College** has spent years exploring a different vector: surreptitious physical access.
### The Subtlety of Sabotage
At the upcoming **Usenix Cybersecurity Conference**, these researchers will present a proof-of-concept hacking technique capable of commandeering a **Boeing 737**'s autopilot. This could redirect its navigation or silently alter critical values in takeoff and fuel calculations, all while spoofing the results displayed to the pilot. Such subtle manipulations, they warn, could lead to anything from runway overruns to diversions into foreign airspace, or even catastrophic crashes.
### The Device: Small, Cheap, and Covert
To execute this attack, the team developed a coin-sized, Wi-Fi-enabled prototype device costing less than $100. This hardware implant can be installed in under a minute into an externally accessible port on the aircraft, routinely within reach of maintenance or airport staff between flights. Once in place, the device can send electrical signals over one of the **737**'s internal networks to spoof commands to sensitive systems governing autopilot and vital flight variables like total weight and outside air temperature.

This decade-long research, involving the purchase of tens of thousands of dollars worth of plane components for testing, aims to expose physical access hacking as a practical threat from well-resourced saboteurs. It offers attackers more control, stealth, and deniability compared to traditional methods like planting a bomb.
"If you could get 60 seconds with an airplane, what could you do?" asks **Stefan Savage**, one of the **UCSD** computer science professors leading the project. "Well, it turns out thereβs a port thatβs externally accessible. You can get to it with no special tools in about 15 seconds. And you can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan.β

### Industry Response and Future Implications
The researchers have shared their findings with **Boeing** for over six years, even demonstrating the attack in a **Boeing** test lab. While **Boeing** stated they reviewed their designs and believe existing protections offer sufficient mitigation, they have not informed the researchers of any technical fixes. Given the infrequent redesigns of commercial aircraft, immediate system updates are unlikely.
Despite the gravity of their findings, the researchers emphasize that this should not cause panic. "All of the authors of this paper routinely travel on **Boeing 737** aircraft and expect to continue doing so," their paper states. However, **Savage** argues for long-term changes in aircraft component cybersecurity and, more immediately, enhanced operational security measures to control physical access to planes on the ground. Simple fixes, such as plugging the vulnerable port with epoxy or removing it entirely, are suggested.
"This is something the aviation industry will want to plan to defend against," **Savage** warns. "I would not sleep on this one."
### From Cars to Planes: A Decade of Research
This team's journey into aviation hacking began almost fifteen years ago, after successfully demonstrating the first over-the-internet techniques for hacking car computer systems, including steering and brakes. Their work, particularly with a **Chevy Impala**'s **OnStar** system, spurred a significant shift in automotive cybersecurity practices, leading to bug bounty programs and the hiring of ethical hackers. Inspired by this success, research scientist **Kirill Levchenko** proposed tackling aircraft. Unable to buy a plane, the team meticulously acquired tens of thousands of dollars worth of **Boeing 737** computer components from the secondhand market, assembling an "avionics test bed" called **Triton** by 2019.