logo

Researchers remotely exploit devices used to manage safe aircraft landings and takeoffs

ID: c8abae70-84a6-5192-b66a-3a609e8693e5

STIX ID: report--c8abae70-84a6-5192-b66a-3a609e8693e5

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2024-02-03

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Researchers found that NAVBLUE's Flysmart+ Manager EFB app had App Transport Security disabled (NSAllowsArbitraryLoads=true), enabling interception and potential manipulation of flight update data (often delivered as SQLite databases). A proof-of-concept showed an attacker within Wi‑Fi range—e.g., at a hotel used by pilots—could modify performance and weight/balance data during monthly AIRAC updates, possibly causing unsafe takeoff/landing calculations; exploitation is considered unlikely in practice, Airbus issued a fix and mitigations were implemented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.