Researchers remotely exploit devices used to manage safe aircraft landings and takeoffs
ID: c8abae70-84a6-5192-b66a-3a609e8693e5
STIX ID: report--c8abae70-84a6-5192-b66a-3a609e8693e5
Feed Name: The Register (Security)
Researchers found that NAVBLUE's Flysmart+ Manager EFB app had App Transport Security disabled (NSAllowsArbitraryLoads=true), enabling interception and potential manipulation of flight update data (often delivered as SQLite databases). A proof-of-concept showed an attacker within Wi‑Fi range—e.g., at a hotel used by pilots—could modify performance and weight/balance data during monthly AIRAC updates, possibly causing unsafe takeoff/landing calculations; exploitation is considered unlikely in practice, Airbus issued a fix and mitigations were implemented.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
