www.heise.de
Mobile Networks Expose IMEI Data During Call Setup
Article Content
A security vulnerability in mobile networks allowed attackers to obtain the IMEI and OS version of a recipient's smartphone before the call was accepted. Research by Bayerischer Rundfunk (BR) revealed that during call setup, the IMEI could be transmitted to the caller, particularly affecting networks from Telekom and Telefónica (O2). The vulnerability was confirmed through 70 test calls, prompting GSMA to alert over 1,000 mobile operators. While Vodafone claimed no IMEI exposure on its network, the Federal Office for the Protection of the Constitution (BfV) indicated that this leak could be exploited by foreign intelligence services. The issue arises from how mobile networks handle call setups, especially when connecting clients from different providers. Although the problem has been acknowledged and addressed by the affected companies, the potential for targeted attacks remains a concern. Experts noted that while the IMEI leak is serious, it does not represent an immediate catastrophic security threat.
Key Points: • IMEI numbers can be leaked during call setup, affecting user privacy. • Telekom and Telefónica (O2) confirmed IMEI exposure; Vodafone denied it. • The GSMA issued an alert to over 1,000 mobile operators to address the vulnerability.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.