AUTONEWS

Study uncovers security weaknesses in next-generation vehicle technology
Georgia Tech researchers have identified seven previously unknown security flaws in next-generation communication standards that connect in-vehicle computers. These flaws create vulnerabilities that could allow attackers to take control of key driver-assistance functions in personal vehicles.
The team also found that the new standard's core rules for sending messages and handling errors retain every known security weakness of older versions.
The vulnerabilities could allow an attacker who has already gained access to a vehicle's internal computer network to change or intercept messages, take individual vehicle computers offline, send different information to different systems, or disrupt network communication.
CAN Extra Long (CAN XL), the latest version of the controller area network (CAN), is designed for future cars and other vehicles that need to move large amounts of data between onboard computers. The technology is not yet widely deployed in production vehicles, giving manufacturers an opportunity to address security concerns before it becomes more common.
“Because it isn't widely deployed yet, we have a narrow window to get its security right,” said Associate Professor Saman Zonouz of the School of Cybersecurity and Privacy and the School of Electrical and Computer Engineering, one of the researchers on the project.
“Fixing a standard now is far easier than fixing it once it's built into the hardware of millions of cars that stay on the road for a decade or more.”
Zonouz said CAN XL is expected to become the primary version of CAN, the network that enables computers inside a vehicle to communicate. It is also expected to serve as the main network for driver-assistance systems in future vehicles.
The researchers confirmed the seven vulnerabilities in commercial CAN XL hardware and demonstrated attacks using a physical test setup that mimics a vehicle network.
Modern vehicles can have dozens of electronic control units that manage systems such as sensors, brakes, steering, and entertainment. These computers need to communicate quickly and reliably.
For decades, many vehicles have used CAN for this communication. However, the original version, known as classic CAN, was not designed to handle the volume of data generated by newer vehicle technologies.
CAN XL was developed to provide faster communication, larger messages, and new security features, but the researchers wanted to know whether the new standard’s basic rules were secure. Their testing revealed that they weren’t. They discovered that an attacker who controls one computer on the network could intercept and replace messages or take a targeted computer offline.
“These flaws are in the standard itself, so every device built to follow it inherits them,” Zonouz said. “With CAN XL, there's still time to fix these problems before they reach the road.”
The attacks would require an attacker to first gain control of a computer connected to the vehicle's internal network. The research does not show that CAN XL itself provides a means to break into a vehicle. Instead, it shows what an attacker could do after gaining access.
Several attacks were also faster and harder to detect than similar attacks against classic CAN, according to the authors.
The researchers proposed changes to the CAN XL rules to prevent several of the attacks. They also recommended additional security measures, including message authentication and systems that can detect unusual activity.
The team reported the vulnerabilities and informed the manufacturers of the commercial devices it tested about the bugs it found. One company has already released a fix. The researchers hope their findings will help manufacturers address security weaknesses before the technology becomes more widely used.
A Formal Security Analysis of CAN XL was published in the Proceedings of the 35th USENIX Security Symposium, held Aug. 12-14 in Baltimore, MD. The paper was also named a runner-up for a distinguished paper award.
The study was conducted by Georgia Tech Ph.D. student ZhaozhouTang, Professor Vijay Ganesh, Zonouz, and Provost and Executive Vice President for Academic Affairs Raheem Beyah, along with Khaled Serag of the Qatar Computing Research Institute and Z. Berkay Celik of Purdue University.
Today’s cars are no longer purely mechanical machines. With in-vehicle infotainment (IVI) systems, telematics, wireless connectivity, advanced driver-assistance systems (ADASs), and cloud services, modern vehicles now function as connected computing platforms on wheels.
As vehicles become more connected and software-defined, the digital attack surface has expanded dramatically. Threat actors are exploiting zero-day vulnerabilities, compromising third-party components, and targeting emerging technologies.
When connected features become attack vectors...At Pwn2Own Automotive 2024 , security researchers from Synacktiv exploited a Tesla Model 3 in about two minutes. The attack began with a rogue GSM signal targeting the vehicle’s modem, then pivoted into the IVI system before gaining control of functions such as the headlights, doors, and trunk.
Two years later, the stakes grew even higher. At Pwn2Own...Automotive 2026, researchers demonstrated remote code execution (RCE) against Alpine and Kenwood head units, while electric vehicle (EV) chargers were compromised to manipulate charging sessions and potentially access backend networks.
These demonstrations highlight how attackers can move from externally exposed interfaces into broader vehicle systems. In many cases, a single vulnerability — particularly in interfaces that are visible, reachable, and behaviorally meaningful to drivers — can become an initial attack vector for multi-stage attacks that spread to other vehicle subsystems.
This pattern is also reflected in VicOne’s 2026 Automotive...Cybersecurity Report. Analysis of 2025 automotive cybersecurity incidents shows that attackers increasingly target in-vehicle systems that drivers interact with directly, with IVI systems among the most frequently targeted components.
Hidden risks in aftermarket accessories...Aftermarket accessories such as dongles and dash cams can introduce significant cybersecurity risks to modern vehicles. Popular devices such as the CarlinKit CPC200-CCPA and the 70mai A51 have been found to ship with hardcoded Wi-Fi passwords, accept unsigned firmware updates via web or USB interfaces, and fail to verify bootloaders or kernels.
An attacker could upload malicious firmware, potentially gaining root access and remote code execution. Once compromised, these accessories can act as persistent backdoors, giving attackers an easy foothold for lateral movement into the rest of the vehicle.
Backdoors in AI-driven vehicle systems...In 2026, researchers demonstrated that targeted poisoning or backdoor attacks are feasible against SuperNet-based AI used in autonomous driving systems. The method, called VillainNet, differs from conventional attacks targeting hardware or firmware. It lurks inside the AI model itself responsible for vehicle perception and decision-making.
The attack only surfaces when specific operational conditions, such as weather or vehicle speed, activate the targeted subnetwork, making it appear normal in most configurations and potentially difficult to detect with traditional static model-based inspection methods.
The discovery highlights a growing blind spot in automotive cybersecurity. As vehicles increasingly rely on AI-based driving intelligence and decision systems, attackers may no longer need to break into the vehicle’s hardware or networks. They can instead manipulate the intelligence that guides how the vehicle interprets and responds to the world.
ADAS: Where automotive cybersecurity meets vehicle safety...As vehicles move closer toward autonomy, advanced driver-assistance systems (ADASs) are emerging as a critical frontier of automotive cybersecurity. Security researchers have demonstrated that even the sensors guiding these systems can be manipulated. A study in 2019 showed that carefully timed laser signals could spoof LiDAR sensors, causing autonomous systems to perceive obstacles that do not exist or fail to detect real ones.
These demonstrations reveal how vulnerabilities in perception...systems can affect the entire driving decision chain. A compromise in one ADAS sensor, for example, can cascade through perception, decision, and control layers, potentially affecting braking, steering, collision avoidance, and other safety-critical functions.
Emerging cyber risks in modern mobility...As vehicles become increasingly connected and software-defined, automotive cyber risks are expanding beyond individual vehicle components to the broader mobility ecosystem. VicOne’s 2026 Automotive Cybersecurity Threat Report highlights several emerging cyber risks that could shape the next phase of automotive cybersecurity. Some of the key predictions include:
AI training data as a new supply chain risk: Attackers may target the datasets used to train automotive AI systems, introducing vulnerabilities that could propagate across multiple vehicle generations.
Fleet-scale OTA compromise: A breach in centralized over-the-air update infrastructure could distribute malicious firmware across entire vehicle fleets.
Cyber risks extending into energy infrastructure: As vehicles integrate with charging networks and Vehicle-to-Grid (V2G) systems, attacks on charging infrastructure could disrupt both mobility services and energy systems.
These emerging risks show how automotive cyber threats are expanding beyond individual vehicles to the broader ecosystem that supports modern mobility.
Researchers at Georgia Tech have identified seven previously unknown security vulnerabilities in the next-generation communication standard known as CAN Extra Long (CAN XL). This technology was developed to connect the internal computers of modern vehicles and enable the rapid exchange of large volumes of data.
As the standard is still under development and has not yet been widely implemented in mass-production vehicles, this discovery offers a crucial opportunity for the automotive industry to fix the flaws before the cars hit the road.
What are the flaws and how do they work?
The study revealed that CAN XL’s fundamental rules for message transmission and error handling retain all the security weaknesses of previous versions (such as the classic CAN):
• Attack prerequisite: The study clarifies that the CAN XL flaws do not provide an initial entry point into the car. An attacker must first gain physical or digital access to the vehicle's internal computer network.
• Attacker capabilities: Once inside the network, the attacker can intercept, alter, or replace messages. They can also disable specific onboard computers (taking them offline), send false information, or disrupt all internal communication.
• Severity: These actions could allow for malicious control of essential driver-assistance functions in passenger vehicles. Furthermore, physical tests demonstrated that CAN XL attacks are faster and considerably harder to detect than those carried out on older systems.
🛠️ Proposed solutions and industry impact
Led by researcher Saman Zonouz, the team proposed direct changes to the CAN XL standard's rules to mitigate risks before its official market debut. Recommendations include:
1. Strict message authentication to ensure instructions originate from a legitimate system.
2. Anomaly detection systems capable of identifying unusual activity within the vehicle's network. The team notified the manufacturers of the commercial devices tested. Demonstrating the urgency of the automotive cybersecurity landscape, one of the responsible companies has already developed and released a fix for its hardware.
Georgia Tech university