logo

Crucial Airline Flight Planning App Open to Interception Risks

ID: c5d5ebd1-258c-58f2-9f95-709547820a75

STIX ID: report--c5d5ebd1-258c-58f2-9f95-709547820a75

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-02-06

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Pen Test Partners disclosed that Navblue's Flysmart+ Manager iOS app had App Transport Security disabled and lacked certificate validation, enabling a man-in-the-middle attack during app updates that could allow tampering with flight performance and planning data; although exploitation requires proximity (e.g., pilot layover Wi‑Fi) and timing during updates, the flaw could lead to incorrect engine power or braking calculations and pose safety risks if abused, and Navblue has since remediated the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.