Researchers Unveil New SIM Card Exploits Threatening Smartphones, IoT Devices, and Network Security

August 25, 2026
Researchers Unveil New SIM Card Exploits Threatening Smartphones, IoT Devices, and Network Security
  • Four attacker scenarios were identified: remote exploitation of SIM software, physical replacement of SIMs, abuse of remote SIM management by compromised operators, and supply-chain manipulation during manufacturing or distribution.

  • Researchers note that the attack surface largely aligns with spec-compliant cellular standards, meaning some attacks could be technically legitimate within existing specs, and they are working with vendors and standardization bodies to remediate risks.

  • The CATana toolkit was created to explore SIM-originating AT commands across 26 devices — 18 smartphones and eight IoT modules in EV chargers, industrial gear, and connected cars — revealing a broad attack surface.

  • The issues are tracked under CVE-2025-48618, CVE-2026-57550, and CVE-2026-0122.

  • Industry response included notifying the GSM Association and affected manufacturers, leading to software updates and hardened configurations to mitigate the attacks.

  • Potential attack capabilities include re-enabling closed debug interfaces, exfiltrating identifiers, sending messages, downgrading networks from 4G to 2G, shutting down devices, and disabling communications, among others.

  • On recent Android devices, a malicious SIM could force a locked phone to open an attacker-controlled website without user interaction, illustrating user-visible risks.

  • Researchers from the University of Birmingham demonstrated that compromised SIM cards can be weaponised to hijack smartphones, EV chargers, and other connected devices by exploiting Proactive SIM to send AT commands to a device’s modem.

Summary based on 1 source


Get a daily email with more Tech stories

Source

Wrong call: Beware of malicious SIM cards

The Citizen • Aug 25, 2026

Wrong call: Beware of malicious SIM cards

More Stories