Hackers Uncover Airbus EFB App Vulnerability, Risking Aircraft Data
ID: e7333f34-d587-5d12-91e3-4134117bf75c
STIX ID: report--e7333f34-d587-5d12-91e3-4134117bf75c
Feed Name: HackRead
Pen Test Partners discovered that the Navblue/Airbus Flysmart+ Manager iOS app had App Transport Security (ATS) deliberately disabled, allowing unencrypted HTTP communications that can be intercepted on untrusted Wi‑Fi (e.g., pilot layover hotels). Researchers were able to retrieve NAVBLUE SQLite databases containing flight- and performance-critical tables, a weakness that could allow modification of take-off performance and other aircraft data; the bug was disclosed in June 2022 and fixed in 2023 after a 19-month window.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
