Physical access to an aircraft has long been treated primarily as a safety and security concern, but not necessarily as a cybersecurity threat. New research from computer scientists at the University of California San Diego challenges that assumption, showing that a person with only a brief opportunity to reach an aircraft’s electronics bay could potentially interfere with the communication systems linking two critical flight computers. In a peer-reviewed study presented at the USENIX Security Symposium in Baltimore, researchers demonstrated a hardware-based attack against a testbed built from genuine Boeing 737 components and aviation software. Their proof-of-concept device was able to manipulate flight-path information and alter data used to assess takeoff conditions, highlighting a rarely examined intersection between airport security, legacy avionics and modern cyber risk.
The attack depends on physical access rather than an internet connection, wireless signal or compromised airline network. The researchers estimate that installing the device would take less than a minute if an attacker could reach an unlocked maintenance port in the aircraft’s Electronics and Equipment bay. Located beneath the nose of the aircraft, the bay can be accessed from the ground and contains essential electronic systems. In normal operations, entry to aircraft and maintenance areas is tightly controlled, yet the researchers argue that brief unauthorized access can never be dismissed entirely. An aircraft parked at a gate, undergoing servicing or positioned in a hangar could, in theory, provide the limited window needed to attach a covert implant.
The vulnerable pathway involves two computers that play central roles in navigation and cockpit information. One is the flight management computer, which helps determine the aircraft’s route, approach path and other operational information. The other is a cockpit display computer that presents pilots with the selected flight path and additional data relevant to flight operations. These systems exchange information through hard-wired communication networks known as data buses. In the Boeing 737 configuration examined by the team, the relevant networks use two ARINC 429 buses, a communications standard developed in the 1970s and widely used in commercial aviation.
ARINC 429 was designed for reliability and predictable communication, not for the type of hostile digital environment associated with contemporary computer networks. Data travels across the system as electrical signals carried by two wires and controlled through defined voltage levels, timing rules and resistor arrangements. Unlike many modern network protocols, the system does not routinely authenticate the origin of every message or cryptographically verify that a command has come from an authorized computer. That design makes the bus dependable under normal conditions but creates a fundamental weakness if an unauthorized device can physically connect to the wiring. A message may appear legitimate because the underlying architecture was not built to distinguish trusted instructions from malicious ones.
To explore that weakness, the researchers built and programmed a small custom hardware device capable of acting as an unauthorized participant on the buses. Rather than simply listening to transmissions, the device was designed to influence the electrical signals on the network. By driving more current onto the lines, it could override or suppress legitimate transmissions and insert its own data. This approach allowed the researchers to alter information moving between the flight management computer and the cockpit display while attempting to conceal evidence that the data had been changed. The technical challenge was not merely sending a false message, but doing so in a way that maintained the timing and electrical behavior expected by the aircraft’s legacy avionics.
In demonstrations on their aircraft testbed, the researchers showed that the implanted device could modify information associated with the aircraft’s planned route. A successful compromise could potentially cause the cockpit system to display an altered path or provide the flight management computer with instructions that redirect the aircraft. The team also demonstrated changes to data involving weight, balance and temperature, information that can influence calculations connected to takeoff performance. Incorrect values could contribute to an unsafe operational picture if they were accepted without detection. The researchers emphasize that pilots and other safeguards could identify or override such changes, but doing so would depend on recognizing that the aircraft’s data had been compromised in the first place.
The findings do not suggest that commercial aircraft can be casually hijacked through a passenger’s laptop or a remote internet attack. The proposed scenario requires significant preparation, specialized electronics expertise and direct access to the aircraft. An attacker would need to understand the target’s avionics configuration, construct and test a compatible device, identify the correct access point and install the hardware without being detected. The researchers also stress that their work was conducted in a controlled environment and was intended to expose a class of vulnerabilities rather than provide a simple, ready-to-use attack. Its significance lies in demonstrating that a short period of physical access can have consequences far beyond the visible act of tampering.
The study focuses on the Boeing 737, one of the most widely used commercial aircraft families in the world, with thousands of aircraft in service. The researchers developed their implementation for the 737 and validated their findings through communication with Boeing, which was informed of the vulnerability in 2020. The team later conducted additional testing in a Boeing laboratory. While aircraft designs differ, the authors believe the broader lesson applies across aviation: legacy communication buses and other systems that were engineered for isolated, trusted environments may require new protections as airports, aircraft and maintenance operations become increasingly connected.
“Our goal with this research is to alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous,” said Aaron Schulman, a UC San Diego computer scientist and cybersecurity researcher and one of the study’s senior authors. Possible defenses could include restricting or redesigning access to maintenance ports, improving inspection procedures, adding physical tamper detection, monitoring unusual electrical activity on avionics buses and introducing stronger authentication at critical communication boundaries. Such measures would have to be evaluated carefully because aviation systems are subject to rigorous certification requirements, and any cybersecurity upgrade must preserve the reliability and timing guarantees on which flight-critical equipment depends.
The work was led by Schulman and Stefan Savage of the UC San Diego Department of Computer Science and Engineering, with contributions from San Crow, Pat Pannuto, Patrick Mercier and Stephen Checkoway. Their research presents a warning that cybersecurity does not begin and end with software updates or network firewalls. In aircraft, the physical architecture of wires, connectors, maintenance panels and decades-old communication standards can be just as important as the digital systems they support. The researchers say the objective is prevention: identifying weaknesses while they remain controllable, before a motivated attacker can combine physical access, specialized engineering and operational opportunity into a genuine aviation threat.
Subject of Research: Experimental cybersecurity study of aircraft avionics
Article Title: Design and Implementation of a Physical Implant Attack on the Boeing 737
News Publication Date: 13-Aug-2026
Web References: https://mediasvc.eurekalert.org/Api/v1/Multimedia/8a123a1f-3ec9-4c24-96bf-6ef4408f4bcc/Rendition/low-res/Content/Public
References: San Crow, Pat Pannuto, Stefan Savage, Aaron Schulman, Patrick Mercier and Stephen Checkoway, “Design and Implementation of a Physical Implant Attack on the Boeing 737,” University of California San Diego and Oberlin College; presented at the USENIX Security Symposium.
Image Credits: Erik Jepsen/University of California San Diego
Keywords
Aircraft cybersecurity, Boeing 737, aviation security, avionics, ARINC 429, flight management computer, cockpit systems, physical cyberattack, aerospace engineering, legacy technology, airport security, computer science

