logo

Hackers Uncover Airbus EFB App Vulnerability, Risking Aircraft Data

ID: e7333f34-d587-5d12-91e3-4134117bf75c

STIX ID: report--e7333f34-d587-5d12-91e3-4134117bf75c

Feed Name: HackRead

Threat Score
75/100

Date Published: 2024-02-01

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Pen Test Partners discovered that the Navblue/Airbus Flysmart+ Manager iOS app had App Transport Security (ATS) deliberately disabled, allowing unencrypted HTTP communications that can be intercepted on untrusted Wi‑Fi (e.g., pilot layover hotels). Researchers were able to retrieve NAVBLUE SQLite databases containing flight- and performance-critical tables, a weakness that could allow modification of take-off performance and other aircraft data; the bug was disclosed in June 2022 and fixed in 2023 after a 19-month window.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.