The automotive industry is currently navigating a critical transition as vehicles evolve from mechanical machines into sophisticated, data-driven platforms. At the heart of this transformation lies the Controller Area Network (CAN), the long-standing communication protocol that enables electronic control units (ECUs) to "talk" to one another. However, as modern vehicles incorporate high-definition cameras, LiDAR systems, and complex artificial intelligence for autonomous driving, the limitations of the original CAN protocol—known as CAN CC—have become glaringly apparent. In response, the industry introduced CAN XL, a next-generation standard designed to provide higher bandwidth and larger data payloads. Yet, a recent study conducted by researchers from the Georgia Institute of Technology, the Qatar Computing Research Institute, and Purdue University suggests that this technological leap may have inadvertently carried forward—and expanded—critical security flaws that have plagued the automotive sector for decades.
The Evolution of In-Vehicle Networking
For nearly four decades, the CAN protocol has functioned as the nervous system of the automobile. Originally developed in the 1980s for internal combustion vehicles with relatively simple electronic requirements, the protocol was built for reliability and cost-efficiency rather than cyber resilience. In the classic CAN environment, messages are broadcast across a shared bus, and because there is no native authentication mechanism, any node on the network can theoretically inject traffic or disrupt communication.
As vehicles became more connected, the vulnerabilities inherent in the CAN bus architecture became a primary concern for cybersecurity researchers. Between 2010 and 2015, high-profile demonstrations of remote vehicle hacking—where researchers gained control over steering, braking, and engine management—highlighted the dangers of an insecure internal bus. While the industry responded with partial solutions, such as CAN FD (Flexible Data-rate), which offered better performance, the underlying architecture remained fundamentally unchanged.
CAN XL was positioned as the comprehensive solution to these throughput and functionality bottlenecks. By supporting up to 2048 bytes of data per frame and significantly increasing bit rates, it promised to bridge the gap between low-speed control networks and high-speed infotainment and autonomous driving systems. However, the study titled "A Formal Security Analysis of CAN XL," presented at the 35th USENIX Security Symposium in August 2026, challenges the assumption that modernization equates to security.
Methodology: Unmasking the MAC Sub-layer
The research team, led by Zhaozhou Tang and colleagues, focused their investigation on the Media Access Control (MAC) sub-layer of the CAN XL protocol. The MAC sub-layer is the foundational component that governs how frames are formatted, how collisions are handled, and how errors are managed on the bus. Historically, this layer has been the entry point for most malicious attacks against automotive systems, as it defines the "rules of the road" for electrical signals moving through the vehicle.
To conduct their analysis, the researchers developed a bit-precise formal model of the CAN XL standard. This model allowed them to mathematically verify the protocol’s behavior under various conditions. By utilizing a formal analysis workflow guided by the specific field-oriented structure of CAN XL, the team sought to identify whether the new standard had addressed the "chronic security weakness" of its predecessor.
The findings were stark. Rather than hardening the protocol against known attack vectors, the redesign appeared to maintain all existing vulnerabilities found in CAN CC. More alarmingly, the researchers identified seven previously unknown vulnerabilities introduced by the changes in the CAN XL specification. These findings indicate that the design choices made to accommodate higher data rates and expanded functionality may have inadvertently created new "side-channels" or logic errors that an attacker could exploit to disrupt vehicle operations.

Validating the Risks: The Testbed Experiment
To move beyond theoretical modeling, the research team implemented a physical testbed using commercial CAN XL controllers. By simulating real-world vehicle traffic patterns—such as data streams from sensors and diagnostic requests—they were able to demonstrate the exploitability of these vulnerabilities through multi-stage attacks.
In these experiments, the researchers performed complex manipulations of the MAC sub-layer, confirming that an attacker could successfully cause bus-off states, bypass error detection mechanisms, or inject malicious control frames that would be accepted by the vehicle’s ECUs as legitimate. Because these attacks target the hardware level of the communication stack, they are particularly difficult to mitigate once a vehicle is deployed on the road. The ability to trigger these vulnerabilities on commercial-grade hardware confirms that the security risks identified in the formal model are not merely academic—they represent a tangible threat to the integrity of future vehicle architectures.
Broader Implications for the Automotive Industry
The publication of this research arrives at a pivotal moment in the automotive supply chain. With major manufacturers currently transitioning their vehicle platforms to CAN XL to accommodate the massive data requirements of autonomous driving and over-the-air (OTA) updates, the security of this protocol is no longer just a technical detail—it is a matter of safety-critical infrastructure.
The implications of these findings are threefold:
- Regulatory and Standardization Challenges: Industry bodies responsible for the CAN XL standard, such as the CAN in Automation (CiA) group, may need to revisit the protocol’s specifications. The researchers have proposed specific mitigations, including the formal verification of future standard revisions, to address the identified weaknesses.
- Increased Burden on Tier-1 Suppliers: Component manufacturers who integrate CAN XL controllers into their ECUs will now face increased scrutiny. There is an urgent need for additional hardware-level security layers, such as hardware security modules (HSMs) or message authentication codes (MACs) implemented at the software level, to compensate for the flaws in the base protocol.
- The Persistence of Legacy Debt: This research serves as a stark reminder of "security debt." By attempting to evolve an architecture that was originally designed for a different era of computing, the industry may be perpetuating a cycle of vulnerability. The study highlights that patching an outdated paradigm often leads to greater complexity, which in turn introduces new, unforeseen attack surfaces.
Official Responses and Future Outlook
While there has been no immediate formal industry-wide recall or total rejection of the CAN XL standard, the automotive security community has largely recognized the significance of the paper. Technical experts have noted that the "formal model" released by the research team is a valuable asset for the industry. By providing a public, bit-precise model of the protocol, the researchers have enabled developers to run their own security audits, potentially accelerating the development of patches or defensive wrappers.
In the long term, the findings may force a shift in how vehicle communication protocols are developed. There is a growing consensus that future automotive networks must move toward architectures that prioritize "secure by design" principles from the ground up, rather than relying on protocols that attempt to maintain backward compatibility with 1980s-era logic.
As the industry looks toward the next generation of software-defined vehicles, the lessons from the CAN XL analysis will likely become part of the standard curriculum for automotive engineers. The transition to CAN XL, while necessary for the technical demands of the 2030s, must now be accompanied by rigorous, formal security verification to ensure that the increased bandwidth of the modern vehicle does not come at the cost of its fundamental safety.
For now, the research provides a clear roadmap for what needs to be fixed. Whether the industry can effectively incorporate these mitigations into existing product cycles before widespread adoption remains the central challenge. The work of Tang and his colleagues underscores that in the realm of automotive cybersecurity, the speed of innovation must be matched by the depth of security analysis, or the industry risks building the future on a foundation that is fundamentally flawed.
