Security researchers from the University of California at San Diego and Oberlin College have demonstrated they can commandeer a Boeing 737's autopilot system in less than a minute using a coin-sized device costing under $100. The team will present their findings tomorrow at the Usenix Cybersecurity Conference, revealing how a hacker with brief physical access to the aircraft could redirect navigation, silently alter critical takeoff and fuel calculations, and spoof results on the pilot's display. The attack works by plugging a Wi-Fi-enabled hardware implant into a port accessible through an exterior hatch that's routinely within reach of maintenance workers or other airport staff between flights, requiring no special tools and taking roughly 15 seconds to access.

Once installed, the device sends electrical signals on one of the 737's internal networks to spoof commands to systems controlling the autopilot and displaying variables like total weight and outside air temperature, which play crucial roles in takeoff calculations. The hacking gadget fits entirely inside the port under a dust cap that normally covers it, hiding it from view, and includes a chip capable of running attack code plus a Wi-Fi radio. That radio would theoretically let the device connect via the plane's in-flight Wi-Fi network and beacon out to whoever controls it, allowing remote operation. The researchers developed the technique over more than a decade, spending tens of thousands of dollars on secondhand Boeing 737 computer components to build what they called Triton, an "avionics test bed" of wired-together plane parts. They first alerted Boeing to their discoveries in spring 2020 and have continued sharing updates for years, even testing and demonstrating their attack in a Boeing facility's test lab.

"If you could get 60 seconds with an airplane, what could you do?" asks Stefan Savage, one of the UCSD computer science professors who led the project, describing the question that first motivated their research. The researchers aren't disclosing which specific port they targeted or releasing some details of how their device spoofs commands to the plane's computers, having worked closely with Boeing to share their findings since first disclosing elements more than six years ago. According to the team's paper, subtle changes enabled by their hack could potentially cause anything from runway overruns on takeoff to diversions into another country's airspace to catastrophic crashes. Boeing responded in a statement that it had conducted its own review of component designs, installations, and interfaces in response to the researchers' findings, but downplayed the practical risk, saying its technical experts are "confident that the layers of protection in place on the airplane" provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.

The researchers say Boeing hasn't told them about any technical fix for the vulnerabilities they've uncovered, and they speculate the company may not implement any such update for years given how rarely commercial airplanes are redesigned. Their work originated nearly 15 years ago when some team members discovered and demonstrated the first successful over-the-internet techniques for hacking a car's computer systems, including steering and brakes, research that ultimately led to a sea change in carmakers' cybersecurity practices. Student researcher Sam Crow discovered that by connecting to a particular 737 bus and sending electrical signals with higher current than legitimate ones, he could override commands with his own, a technique they dubbed "Bus Driver." Tricking the pilot into thinking outside air was colder or the plane's load lighter than reality could prevent the 737 from achieving necessary speed for takeoff before running out of runway, while flight plan tampering could cause the autopilot to enter another country's airspace where it might be commandeered by that country's air force.

The researchers outline fixes ranging from removing the vulnerable connector altogether or plugging it with epoxy to longer-term software updates that detect their hacking technique, better electrically isolate systems, or add cryptographic authentication to prevent signal spoofing. Their simplest recommendation is immediate: plug the port with epoxy or remove it entirely. "This is something the aviation industry will want to plan to defend against," Savage says. "I would not sleep on this one." The paper notes that calling for these updates across the aviation industry isn't alarmist given the attack's practicality, and all authors routinely travel on Boeing 737 aircraft and expect to continue doing so. Cybersecurity consultant Beau Woods, who has advised the Cybersecurity and Infrastructure Security Agency and served on Boeing's Industry Cyber Technical Council, says the research "looks like solid empirical evidence about some realistic scenarios for high-capability adversaries," noting it's entirely possible for staff to access a plane during ground maintenance and install such a device. The threat model for highly sensitive systems must evolve as attackers' technology advances, particularly as entire hardware setups capable of connecting to a plane's Wi-Fi and relaying commands can now fit onto a tiny disc hidden inside an obscure plug's dust cap. Commercial aviation's reliance on physical security assumptions may need urgent recalibration as adversaries gain access to miniaturized tools that weren't imaginable when current aircraft were designed.