CAN has been the backbone of in-vehicle communication for decades, but its limits in bandwidth and security have pushed the industry toward CAN XL, a next-generation standard promising longer payloads, higher throughput, and built-in security features. Whether those features actually fix the root cause of CAN's chronic weaknesses—the MAC sub-layer, which controls frame formats and error handling—had not been rigorously tested until now.

Researchers from Georgia Institute of Technology, Qatar Computing Research Institute, and Purdue University built a bit-precise formal model of CAN XL and analyzed its MAC sub-layer. Contrary to expectations, they found CAN XL remains vulnerable to every known CAN CC MAC sub-layer issue and introduces seven new vulnerabilities of its own, arguably making security worse.

The team validated the findings using commercial CAN XL controllers and demonstrated exploitability through two multi-stage attacks on a testbed simulating real vehicle traffic. They also proposed mitigations, including formally verifying standard revisions to prevent several of the identified attacks. The paper is set to appear at the 35th USENIX Security Symposium in August 2026.