Mobile Networks Expose IMEI Data During Call Setup

Mobile Networks Expose IMEI Data During Call Setup

First seen 28 Aug 2026, 01:25 UTC Cybernewswww.heise.de 61.0

Article Content

Browse articles
ThreatCluster

A security vulnerability in mobile networks allowed attackers to obtain the IMEI and OS version of a recipient's smartphone before the call was accepted. Research by Bayerischer Rundfunk (BR) revealed that during call setup, the IMEI could be transmitted to the caller, particularly affecting networks from Telekom and Telefónica (O2). The vulnerability was confirmed through 70 test calls, prompting GSMA to alert over 1,000 mobile operators. While Vodafone claimed no IMEI exposure on its network, the Federal Office for the Protection of the Constitution (BfV) indicated that this leak could be exploited by foreign intelligence services. The issue arises from how mobile networks handle call setups, especially when connecting clients from different providers. Although the problem has been acknowledged and addressed by the affected companies, the potential for targeted attacks remains a concern. Experts noted that while the IMEI leak is serious, it does not represent an immediate catastrophic security threat.

Key Points: • IMEI numbers can be leaked during call setup, affecting user privacy. • Telekom and Telefónica (O2) confirmed IMEI exposure; Vodafone denied it. • The GSMA issued an alert to over 1,000 mobile operators to address the vulnerability.

Timeline

2026-08-27
Cybernews reports IMEI leak vulnerability
Cybernews highlighted a critical vulnerability allowing IMEI leaks during call setup, confirmed by BR's investigation.
Cybernews
2026-08-28
Heise.de publishes details on IMEI transmission
Heise.de reported that IMEI numbers were transmitted to callers before call acceptance, affecting multiple networks.
Heise.de
Recent
GSMA issues alert to mobile operators
The GSMA alerted over 1,000 mobile network operators to check their systems for the vulnerability.
Cybernews