< Back to all clusters
[TECHNOLOGY] · United States, United Kingdom · 7 sources

started · updated

Malicious SIM cards can hijack smartphones and IoT devices

Researchers from the University of Birmingham and security firm Fuzzware have demonstrated that malicious or compromised SIM cards can serve as an entry point to hijack smartphones and IoT devices. Presented at the USENIX WOOT conference, the study highlights vulnerabilities in the “Proactive SIM” feature, which allows cards to send AT commands to a device's modem.

Using a tool called CATana, the team tested 26 devices, including 18 smartphones and eight IoT modules. They found that nine devices—including several IoT modules used in electric vehicle chargers, industrial routers, and vehicle telemetry units—exposed the SIM AT command interface. This exposure allows attackers to execute arbitrary code, steal files, perform denial-of-service attacks, or force connections to downgrade from 5G to 2G.

Specific vulnerabilities were identified in hardware from Quectel and certain smartphone models like the Oppo Reno14 F 5G and ASUS Zenfone 9. In one instance, researchers successfully used a malicious SIM to gain code execution privileges on an Autel electric vehicle charger. Google has addressed a related vulnerability (CVE-2025-48618) that allowed malicious SIMs to trigger the “LAUNCH BROWSER” command on certain Android versions without user interaction. Qualcomm has responded by developing a secure configuration that disables the SIM AT interface by default.

Entities

Fuzzware · Google · Qualcomm · Quectel · USENIX WOOT 2026 · University of Birmingham