Skip to main content
See every side of every news story
Published loading...Updated

How Malicious SIM Cards Can Hijack Smartphones, EV Chargers and Connected Devices

Researchers said 26 test devices exposed SIM-to-modem commands that enabled code execution, data theft and remote shutdown without user interaction.

  • At the 2026 USENIX WOOT Conference in Baltimore, researchers from the University of Birmingham and Fuzzware revealed that malicious Subscriber Identity Module cards pose severe, overlooked security risks to cellular devices including smartphones and electric vehicle chargers.
  • A built-in feature known as 'Proactive SIM' allows a card to issue commands directly to a device's modem. Assistant Professor Marius Muench noted these legacy capabilities, created in the 1980s, create an attack surface that remains 'specification-compliant.'
  • Using a custom tool named CATana, researchers tested 26 representative devices, finding nine exposed an AT command interface. On one Oppo Reno14, they identified 198 commands enabling attackers to downgrade connection security from 4G to vulnerable 2G networks and execute code.
  • Google patched Android 13 through 16 for CVE-2025-48618 following researcher disclosure, while Qualcomm produced a hardened configuration disabling the SIM AT interface by default. The GSMA is tracking the issue as CVD-2026-0122.
  • Kristian Covic of Fuzzware noted that hostile SIMs remain missing from many threat models despite leaked intelligence documents demonstrating risks. Researchers suggest retiring risky proactive SIM functionality like RUN AT as the best long-term solution.
Insights by Ground AI

17 Articles

Lean Left

The SIM card, in its traditional physical version as well as in the latest eSIM, is indispensable to connect to mobile networks. But that small card that identifies our telephone line can hide a much greater risk than you thought: a compromised SIM can in fact become an entrance door for computer attacks capable [...] The article The SIM that turns into a weapon: so a compromised card can attack smartphones and connected cars comes from The Dail…

·Rome, Italy
Read Full Article
Lean Left

Researchers from the University of Birmingham and the cybersecurity company Fuzzware have discovered SIM card-related vulnerabilities in mobile phones and electric vehicle chargers. According to the research, a malicious or compromised SIM card could create a vulnerability in the connected device without the user performing any action.

·Türkiye
Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 60% of the sources are Center
60% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

TechXplore broke the news in Douglas, United Kingdom on Monday, August 10, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal