The port carries data between the Flight Management Computer (FMC) and the pilot's Multi-purpose Control Display Unit (MCDU) over two ARINC 429 buses — a hard-wired communication standard dating to 1977 that lacks message authentication or encryption .
The implant acts as a "bus driver" by driving more current on the bus than the legitimate computers, allowing it to override any transmissions and inject its own spoofed commands. It can also suppress indications on the pilot's display that changes have been made .
The researchers first disclosed the vulnerability to Boeing in 2020 and later validated their findings in a Boeing test facility . Boeing confirmed it carried out a review of its components' designs and interfaces, and told WIRED that "the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks"
. The researchers say Boeing has not told them about any technical fix. They speculate the company may not implement an update for years, given how rarely commercial airplanes are redesigned
.