Researchers show coin-sized device can hack Boeing 737 autopilot in under a minute
Security researchers have revealed a critical vulnerability that could allow an attacker to hijack an aircraft’s autopilot system within a minute. By opening a standard exterior hatch and inserting a small, low‑profile device, the attackers can re‑route the aircraft’s flight plan or override its autopilot controls. The device exploits a flaw in the aircraft’s external power and data interfaces, which are normally considered secure against such intrusions.
The demonstration was carried out on a commercial airliner model that is widely used by major carriers. While the researchers did not disclose the exact make or model, they confirmed that the technique works on any aircraft equipped with the same type of external power connectors and flight‑control data links. Aviation regulators and manufacturers have been notified, and investigations are underway to assess the scope of the vulnerability and to develop countermeasures, including hardened access controls and software‑based authentication of external devices.
Industry officials warn that the discovery underscores the need for tighter security around aircraft maintenance interfaces. The FAA and EASA are expected to issue guidance on patching the flaw and reviewing existing maintenance procedures. Until a fix is deployed, airlines may restrict access to exterior hatches and enforce stricter verification protocols for any devices connected to the aircraft’s systems.