Wed 12 Aug 2026 / 11:07 ET
Kernel
Internet 3 min read

Boeing 737 hack device requires physical access, researchers say

Researchers say a small implant can spoof signals on a 737 test setup, while Boeing says existing protections limit real-world risk.

Riley Okafor

By Riley Okafor / Senior AI Reporter

Boeing 737 hack device requires physical access, researchers say
img: WIRED

A reported boeing 737 hack device is a physical-access proof of concept, not a tool an outsider can use to seize an aircraft remotely in flight. Researchers from the University of California, San Diego and Oberlin College say they built a small hardware implant that must be placed in an externally accessible aircraft port while the plane is on the ground, according to WIRED.

The research raises an awkward security question for airlines and airports: what happens if someone with brief access to an aircraft between flights can connect hardware to its internal systems? The team says its prototype is roughly coin-sized, Wi-Fi-enabled and costs less than $100. It reported that the implant can be fitted in under a minute through an exterior hatch accessible to maintenance workers and other airport or airline staff.

Can the Boeing 737 hack device remotely take over a plane?

No such capability is described in the report. The demonstrated scenario depends on an attacker physically reaching the aircraft and installing the device before it can transmit signals on an internal network. The researchers have withheld the particular port they used and parts of the command-spoofing method, which is sensible given the subject matter and leaves outside readers unable to assess the full technical chain.

According to the researchers’ account, the implant could impersonate signals sent to systems involved in autopilot navigation. They also said it could alter values displayed to pilots, including inputs such as aircraft weight and outside air temperature that feed into takeoff calculations. The claimed consequences, including navigation changes or corrupted takeoff and fuel calculations, come from the research team’s test work. They are not evidence of a confirmed compromise of an in-service aircraft.

The team spent years assembling a 737 avionics test bed from secondhand components, WIRED reported. It said the researchers first shared parts of their findings with Boeing more than six years ago and later tested and demonstrated the attack in a Boeing facility’s test lab.

What did Boeing say about the reported attack?

Boeing told WIRED that it reviewed the relevant component designs, installations and interfaces after receiving the findings. The company said protections in the aircraft’s design and operating environment significantly reduce both the feasibility and risk of a real-world attack.

The researchers said Boeing had not told them of a technical remedy. That does not establish that no mitigation exists, nor does the available reporting show whether Boeing changed any hardware or procedures. It also does not identify which 737 variants may be affected, or provide an independent regulatory assessment.

The paper’s authors did not call for aircraft to be grounded and said they routinely fly on 737s and expect to keep doing so. Their proposed response focuses on tighter control of access while planes are on the ground, alongside longer-term security changes to aircraft components. One suggested measure was to block or remove the accessible port.

The distinction is doing most of the work here. This is a reported demonstration of a risk created by physical access to an aircraft, not confirmation that passenger Wi-Fi, a laptop in a seat, or a distant internet connection can hijack a Boeing 737.

This story draws on original reporting from WIRED.

More Internet/

view all ↗