Researchers at the University of California San Diego and Oberlin College demonstrated Bus Driver, a physical proof-of-concept attack against Boeing 737 avionics in a laboratory testbed. A coin-sized implant costing less than $100 can reportedly be installed in under a minute through an externally accessible, non-locking panel or unused ground-accessible maintenance connection in the electronics and equipment bay, where it injects stronger signals onto an ARINC 429 bus.
The device targeted communications between the flight-management computer and multifunction cockpit displays, enabling falsification of takeoff and landing inputs, changes to autopilot routing and operational data, and potential concealment of changes on the affected display. The researchers disclosed the issue to Boeing in 2020 and said the work was validated in Boeing laboratories; Boeing stated that layered safeguards substantially limit real-world feasibility and risk. Pilots may identify discrepancies on other cockpit displays and retain manual control, while the status of any mitigations has not been publicly disclosed.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
UC San Diego researchers published and presented research at the USENIX Security Symposium in Baltimore describing a proof-of-concept implant that accesses Boeing 737 ARINC 429 avionics buses through an unsecured ground-accessible maintenance port. The device was shown in a laboratory testbed to override bus messages and manipulate route or takeoff-related data, potentially while concealing changes on the cockpit interface.
Following the researchers' 2020 disclosure, Boeing permitted validation of the Bus Driver-based FMC/MCDU mediation attack in its own 737 test environment. The researchers reported a successful demonstration in December 2023.
University of California San Diego and Oberlin College researchers notified Boeing about the physical avionics-security findings, including the accessible maintenance-port attack vector. The researchers recommended restricting access to the port and strengthening bus protections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcekaspersky.ru
Open sourcecyberveille.ch
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.