Malicious SIM Cards Exploit Vulnerabilities in Smartphones and IoT Devices

Malicious SIM Cards Exploit Vulnerabilities in Smartphones and IoT Devices

First seen 10 Aug 2026, 11:02 UTC Birmingham.Ac.Ukwww.usenix.org 80% similarity 67.5

Article Content

Browse articles
ThreatCluster

Researchers from the University of Birmingham presented findings on the security risks posed by malicious SIM cards at the 2026 USENIX WOOT Conference. Their study revealed that 9 out of 26 analyzed devices, including smartphones and IoT modules, expose a SIM AT interface that can be exploited through SIM-originating AT commands. The CATana toolkit was developed to demonstrate these vulnerabilities, resulting in the discovery of four significant security flaws, including command execution and Denial-of-Service attacks. The risks are particularly concerning for IoT devices, which often have limited interfaces. Despite previous warnings about hostile SIMs, the threats remain largely unaddressed in current threat models. The research emphasizes the need for hardening or disabling the SIM AT interface to mitigate these risks.

Key Points: • Nine out of 26 devices analyzed expose a vulnerable SIM AT interface. • Four significant vulnerabilities were discovered, including command execution and DoS. • The CATana toolkit was developed to explore and demonstrate these SIM-originating threats.

ThreatCluster AI How this analysis works

Timeline

2025-12-08
CVE-2025-48618 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-10
Research presented at USENIX WOOT Conference
University of Birmingham researchers revealed vulnerabilities in SIM cards that can hijack smartphones and IoT devices.
Birmingham.Ac.Uk
2026-08-10
CATana toolkit introduced
The CATana toolkit was developed to analyze the security risks associated with SIM-originating AT commands across various devices.
www.usenix.org
Recent
Discovery of vulnerabilities in devices
The research identified four vulnerabilities in devices that expose the SIM AT interface, including command execution and Denial-of-Service.
Birmingham.Ac.Uk

Community

Browse all →

Tracked Entities in This Story