The 'Bus Driver' attack, presented at USENIX Security '26 by researchers from UC San Diego and Oberlin College, uses a coin sized device costing under $100 that physically plugs into an externally accessible maintenan... The device can alter flight plans, change takeoff variables (aircraft weight and outside air tem...
Research answer

Create a landscape editorial hero image for this Studio Global article: What is the "Bus Driver" attack presented at the Usenix Security Symposium, including how researchers used a coin-sized, sub-$100 Wi-Fi devi. Article summary: The "Bus Driver" attack is a research demonstration presented at the 2026 USENIX Security Symposium by a team from UC San Diego and Oberlin College. It uses a coin-sized Wi-Fi device costing under $100 that can be physic. Topic tags: general, academic, general web, user generated, education. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, water
Presented at the 2026 USENIX Security Symposium, the 'Bus Driver' attack is among the most practical aircraft hacking demonstrations ever made public. A team from UC San Diego and Oberlin College built a coin-sized Wi-Fi device that costs under $100, can be physically installed on a Boeing 737 in less than 60 seconds, and can take control of the plane's autopilot by injecting commands over the unencrypted ARINC 429 avionics bus .
An attacker begins by opening an unsecured hatch on the aircraft's exterior—the Electronics and Equipment (E&E) bay—in roughly 15 seconds with no special tools . Inside, a diagnostic maintenance port used by ground crews for testing and troubleshooting avionics is directly wired to the Flight Management Computer (FMC) and the cockpit's Multipurpose Control Display Unit (MCDU) over the ARINC 429 bus
.
The researchers' custom device, which is roughly the size of a coin (slightly larger than a U.S. quarter), plugs into this port and fits entirely under the existing dust cover, rendering it invisible during casual inspection. The total installation takes under 60 seconds .
Once connected, the device uses a technique the researchers call 'Bus Driver'—sending signals at a higher electrical current to override and replace genuine commands transmitted between the FMC and MCDU. Because the ARINC 429 protocol has no encryption or authentication, the device can intercept, modify, and inject messages without detection . The device also includes a Wi-Fi module, allowing an attacker to control it remotely through an aircraft's onboard Wi-Fi network
.
The 'Bus Driver' device grants an attacker several forms of control over the aircraft's avionics:
The researchers warn that these capabilities could lead to serious outcomes:
Boeing stated it is 'confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks' . However, the researchers report that Boeing was first notified of elements of the research more than six years ago, around 2020, and has not disclosed any specific technical fix to address the vulnerability
.
The researchers propose both short-term physical fixes and longer-term engineering solutions:
Short-term physical fixes
Long-term software/hardware fixes
Despite the severity of the demonstration, the researchers emphasize that they continue to fly on Boeing 737s themselves. They are not calling for grounded aircraft but instead advocate for long-term industry planning to address this class of physical-access avionics attacks .
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The 'Bus Driver' attack, presented at USENIX Security '26 by researchers from UC San Diego and Oberlin College, uses a coin sized device costing under $100 that physically plugs into an externally accessible maintenan...
The 'Bus Driver' attack, presented at USENIX Security '26 by researchers from UC San Diego and Oberlin College, uses a coin sized device costing under $100 that physically plugs into an externally accessible maintenan... The device can alter flight plans, change takeoff variables (aircraft weight and outside air temperature), and spoof pilot displays to hide these modifications—potentially causing runway overruns or diversion into res...
Boeing says existing protections 'significantly limit the feasibility' of real world attacks, but the researchers note no specific technical fix has been disclosed in the six years since Boeing was first notified.