paper

S12X Patch Diffing with QBinDiff

arXiv:2608.05350

Abstract

This paper presents a reverse engineering analysis of a firmware update for a commercial vehicle Brake ECU. We analyze the updater executable to extract firmware and perform differential binary analysis of the S12X architecture firmware images. Our research identifies specific changes in the recall that address undocumented vulnerabilities in legacy protocol processing. We demonstrate that the patched functionality contained critical flaws. The findings confirm the safety recall remediation was also a security patch.

Preprint of paper to be presented at VehicleSec 2026. This version includes appendices beyond the page limits of the conference

S12X Patch Diffing with QBinDiff · wovepaper