logo

Hacking Electronic Flight Bags. Airbus NAVBLUE Flysmart+ Manager

ID: 7e2f260d-b37c-5fa6-b32b-5914f786913f

STIX ID: report--7e2f260d-b37c-5fa6-b32b-5914f786913f

Feed Name: Pen Test Partners Blog

Threat Score

Date Published: 2024-02-01

Date Updated: 2026-03-24

Author: Antonio Cassidy

...
...

Researchers found that the Flysmart+ Manager iOS EFB app from Airbus/NAVBLUE had App Transport Security and certificate validation disabled, permitting insecure HTTP traffic and exposing pilots to man‑in‑the‑middle attacks on untrusted Wi‑Fi that could tamper with performance and operational data (e.g., engine calculations, runway info). The issue, visible via intercepted downloads including SQLite databases, posed safety risks unlikely to be caught by SOP cross‑checks; Airbus confirmed, replicated, and remediated the flaw after coordinated disclosure, aligning fixes with aviation’s longer certification timelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.