Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 23 sources · 1 days · First seen · Last updated
SIM card security vulnerabilities in mobile and IoT devices
Overview
Researchers from the University of Birmingham and security firm Fuzzware have identified vulnerabilities in the ‘Proactive SIM’ feature, which allows SIM cards to send AT commands to a device’s modem. Using a tool called CATana, the team tested 26 devices, including smartphones and IoT modules used in industrial routers, vehicle telemetry units, and electric vehicle chargers.
The study demonstrated that compromised SIM cards can serve as entry points to hijack devices, execute arbitrary code, steal files, or perform denial-of-service attacks. A key risk identified is the ability for attackers to force connections to downgrade from 5G or 4G to older, less secure 2G networks.
Specific hardware vulnerabilities were noted in Quectel modules and certain smartphone models, such as the ASUS Zenfone 9 and Oppo Reno14 F 5G. In response to these findings, Google has addressed a related vulnerability involving the ‘LAUNCH BROWSER’ command, and Qualcomm is developing a secure configuration to disable the SIM AT interface by default.
Entities
Fuzzware · University of Birmingham · Google · Munich Police · Marius Muench
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 3 SOURCES] The guide was produced in partnership with Computerwissen.de.
- [● 3 SOURCES] Android smartphones and many MP3 players allow music transfer via USB cable without specialized software.
- [● 3 SOURCES] Users must select the 'File Transfer' mode on Android devices when connecting to a Windows PC.
- [● 3 SOURCES] Music files must be stored as files on the Windows PC to be transferred via this method.
- [● 3 SOURCES] The USB transfer method described does not apply to iPhones.
Timeline
-
15 days ago
[TECHNOLOGY] 16 sourcesUniversity of Birmingham researchers identify SIM card security risksUniversity of Birmingham researchers warn that SIM card vulnerabilities, specifically the ‘Proactive SIM’ function, could allow attackers to compromise smartphones, vehicles, and industrial equipment.
-
16 days ago
[TECHNOLOGY] 7 sourcesMalicious SIM cards can hijack smartphones and IoT devicesResearchers have revealed that malicious SIM cards can hijack smartphones and IoT devices, such as EV chargers, by exploiting the Proactive SIM feature to execute unauthorized commands via the device modem.
Sources
apach57.fr · borncity.com · extratipp.com · fehmarn24.de · finance.technews.tw · infoguerra.com.br · kreiszeitung.de · kurierverlag.de · leinetal24.de · media.merkur.de · merkur.de · muenchner-merkur.de · ocio.diariodemallorca.es · ocio.farodevigo.es · op-online.de · ruhr24.de · skor.sozcu.com.tr · storage-insider.de · tn.com.ar · tz-online.de · tz.de · vlv.hu · wochentlich.de