# SIM card security vulnerabilities in mobile and IoT devices

> Live situation record from CLSTR: https://clstr.news/situations/sim-card-security-vulnerabilities-in-mobile-and-iot-devices
> Updated: 2026-08-12T08:15:39.000Z. Sources: 23. Developments: 2.

Researchers from the University of Birmingham and security firm Fuzzware have identified vulnerabilities in the ‘Proactive SIM’ feature, which allows SIM cards to send AT commands to a device’s modem. Using a tool called CATana, the team tested 26 devices, including smartphones and IoT modules used in industrial routers, vehicle telemetry units, and electric vehicle chargers.

The study demonstrated that compromised SIM cards can serve as entry points to hijack devices, execute arbitrary code, steal files, or perform denial-of-service attacks. A key risk identified is the ability for attackers to force connections to downgrade from 5G or 4G to older, less secure 2G networks.

Specific hardware vulnerabilities were noted in Quectel modules and certain smartphone models, such as the ASUS Zenfone 9 and Oppo Reno14 F 5G. In response to these findings, Google has addressed a related vulnerability involving the ‘LAUNCH BROWSER’ command, and Qualcomm is developing a secure configuration to disable the SIM AT interface by default.

## Claims

- The guide was produced in partnership with Computerwissen.de. (corroborated by 3 sources)
- Android smartphones and many MP3 players allow music transfer via USB cable without specialized software. (corroborated by 3 sources)
- Users must select the 'File Transfer' mode on Android devices when connecting to a Windows PC. (corroborated by 3 sources)
- Music files must be stored as files on the Windows PC to be transferred via this method. (corroborated by 3 sources)
- The USB transfer method described does not apply to iPhones. (corroborated by 3 sources)

## Timeline

### 2026-08-12: University of Birmingham researchers identify SIM card security risks

University of Birmingham researchers warn that SIM card vulnerabilities, specifically the ‘Proactive SIM’ function, could allow attackers to compromise smartphones, vehicles, and industrial equipment.

16 sources. https://clstr.news/cluster/android-and-mp3-players-how-to-transfer-music-via-usb

### 2026-08-11: Malicious SIM cards can hijack smartphones and IoT devices

Researchers have revealed that malicious SIM cards can hijack smartphones and IoT devices, such as EV chargers, by exploiting the Proactive SIM feature to execute unauthorized commands via the device modem.

7 sources. https://clstr.news/cluster/sim-card-vulnerabilities-allow-attacks-on-smartphones-and-ev-chargers

---
Cite as: SIM card security vulnerabilities in mobile and IoT devices. CLSTR, https://clstr.news/situations/sim-card-security-vulnerabilities-in-mobile-and-iot-devices
