How Malicious SIM Cards Can Hijack Smartphones, EV Chargers and Connected Devices
Researchers said 26 test devices exposed SIM-to-modem commands that enabled code execution, data theft and remote shutdown without user interaction.
- At the 2026 USENIX WOOT Conference in Baltimore, researchers from the University of Birmingham and Fuzzware revealed that malicious Subscriber Identity Module cards pose severe, overlooked security risks to cellular devices including smartphones and electric vehicle chargers.
- A built-in feature known as 'Proactive SIM' allows a card to issue commands directly to a device's modem. Assistant Professor Marius Muench noted these legacy capabilities, created in the 1980s, create an attack surface that remains 'specification-compliant.'
- Using a custom tool named CATana, researchers tested 26 representative devices, finding nine exposed an AT command interface. On one Oppo Reno14, they identified 198 commands enabling attackers to downgrade connection security from 4G to vulnerable 2G networks and execute code.
- Google patched Android 13 through 16 for CVE-2025-48618 following researcher disclosure, while Qualcomm produced a hardened configuration disabling the SIM AT interface by default. The GSMA is tracking the issue as CVD-2026-0122.
- Kristian Covic of Fuzzware noted that hostile SIMs remain missing from many threat models despite leaked intelligence documents demonstrating risks. Researchers suggest retiring risky proactive SIM functionality like RUN AT as the best long-term solution.
17 Articles
17 Articles
The SIM card, in its traditional physical version as well as in the latest eSIM, is indispensable to connect to mobile networks. But that small card that identifies our telephone line can hide a much greater risk than you thought: a compromised SIM can in fact become an entrance door for computer attacks capable [...] The article The SIM that turns into a weapon: so a compromised card can attack smartphones and connected cars comes from The Dail…
Researchers from the University of Birmingham and the cybersecurity company Fuzzware have discovered SIM card-related vulnerabilities in mobile phones and electric vehicle chargers. According to the research, a malicious or compromised SIM card could create a vulnerability in the connected device without the user performing any action.
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers have found that a malicious SIM card can tell some phones and cellular-connected devices to leak data, drop to 2G, shut themselves down, or even execute code, all thanks to functionality that's supposed to be there. The research [PDF], presented at the USENIX WOOT conference in Baltimore this week, examines proactive SIM functionality, which allows a SIM to issue commands to the device hosting it. One of those is RUN AT, which allows…
Security researchers discover SIM card vulnerabilities in mobiles, EV chargers
We treat SIM cards like harmless chips, but they are fully functioning mini-computers. And right now, it could be working against you. At the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore, cybersecurity researchers from the University of Birmingham and security firm Fuzzware revealed that malicious or compromised Subscriber Identity Module (SIM) cards pose severe, overlooked security risks to cellular devices. It could quiet…
How malicious SIM cards can hijack smartphones, EV chargers and connected devices
Subscriber Identity Modules (SIMs), secure elements used to connect devices to a mobile network, can pose severe security risks when compromised. A malicious SIM could allow attackers to gather information about a device, interfere with its connectivity and serve as an entry point for further cyberattacks.
Hidden SIM Card Vulnerability Affecting Smartphones, EV Chargers and IoT Devices
Security researchers from Birmingham University unveiled research at USENIX WOOT Conference 2026 on Offensive Technologies, demonstrating how a… This article has been indexed from Hackers Online Club Read the original article: Hidden SIM Card Vulnerability Affecting Smartphones, EV Chargers and IoT Devices The post Hidden SIM Card Vulnerability Affecting Smartphones, EV Chargers and IoT Devices appeared first on IT Security News.
Coverage Details
Bias Distribution
- 60% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium















