Nine of 26 Tested Devices Took Commands From Their SIM Cards
Science

Nine of 26 Tested Devices Took Commands From Their SIM Cards

Researchers found that nine of 26 tested phones and cellular IoT modules accepted modem commands from a hostile SIM, enabling effects from lost connectivity to code execution. The attack requires control of a SIM or eSIM, and vendors have already patched or hardened several affected systems.

NewTqnia Science Desk 5 min read
Nine of 26 Tested Devices Took Commands From Their SIM Cards

A SIM card is usually treated as a trusted key that connects a phone or machine to a mobile network. New peer-reviewed security research shows why that trust can be dangerous: nine of 26 tested devices accepted modem commands originating from the SIM, opening paths to data theft, lost connectivity and, in some cases, code execution.

The 30-second summary

  • What happened? Researchers tested 18 smartphones and eight cellular Internet of Things modules with a toolkit called CATana. Nine devices exposed an interface that allowed a hostile SIM to issue modem-control commands.
  • Why does it matter? Cellular modules are embedded in phones, routers, cars, industrial equipment, payment terminals and electric-vehicle chargers, often as one of the few interfaces available.
  • What is the catch? An attacker first needs a malicious or compromised physical SIM or eSIM. This is not an attack that an ordinary website can launch against any nearby phone.

KEY NUMBER
9 of 26 tested devices exposed the SIM command interface, and the researchers reported four vulnerabilities.

Why can a SIM send commands at all?

A SIM is a small computer, not just a passive identity chip. Cellular standards include proactive SIM functions that let it request actions from the device. One of those functions can ask the modem to run AT commands, a command language that has controlled modems since the dial-up era.

The researchers call the resulting path a SIM AT interface. Their CATana paper at the USENIX WOOT conference, presented on August 10, argues that manufacturers often designed this interface under the assumption that the SIM was trustworthy. A hostile SIM turns that design assumption into an attack surface.

This is less like a stranger attacking a phone across the internet and more like giving a malicious component a privileged seat inside the device. The risk becomes especially important for locked-down equipment whose cellular module may otherwise expose few ways to interact with its software.

What did the researchers demonstrate?

The team built CATana to generate SIM-originating commands and observe how real equipment responded. The test set included 18 smartphones and eight cellular-connected modules used in Internet of Things products. Nine of the 26 devices exposed the interface, according to the full peer-reviewed conference paper.

Depending on the device, demonstrated effects included reading files or unique identifiers, re-enabling debugging interfaces, making calls or sending messages, disabling cellular service, shutting equipment down and forcing a downgrade from 4G to the less secure 2G network. One case reached arbitrary command execution on a communication processor.

The researchers also found that a malicious SIM could make recent Android devices open an attacker-controlled web page while the phone was locked. That issue became CVE-2025-48618 and was addressed in the December 2025 Android security bulletin.

How could a hostile SIM reach a real device?

The paper describes four routes. An attacker might exploit a weakness in SIM software remotely, physically replace a SIM, compromise an operator's remote SIM-management system, or alter cards during manufacturing and distribution. The same broad concern applies to eSIM profiles because they can also be provisioned and managed as software.

These prerequisites sharply limit the immediate consumer threat. A random message, application or website does not automatically gain the ability to impersonate the SIM. Successful exploitation requires control over a component or management channel that most users cannot directly inspect.

However, the consequences can be broader in supply-chain or operator compromise. One malicious profile could reach devices that owners assume are sealed and trustworthy, including equipment deployed remotely for years.

Before we overstate the result

  • The sample contained 26 representative devices, not every phone, modem or connected product on the market.
  • Only nine devices exposed the tested interface, and specific impacts differed by hardware and software configuration.
  • The study demonstrates technical possibility under hostile-SIM conditions. It does not report mass exploitation of these flaws in the wild.
  • Several affected vendors had already released updates or hardened configurations during coordinated disclosure.

Why connected machines may matter more than phones

Phones receive visible operating-system updates and are regularly replaced. Industrial modules, routers, vehicle systems and charging equipment can remain in service much longer, while their owners may not know which modem firmware or SIM functions they use.

This makes the research more consequential than a dramatic phone-hacking headline suggests. A forced network downgrade or disabled connection can interrupt a machine that relies on cellular service for payment, monitoring or remote control, even when the attacker never takes over its main application processor.

The researchers coordinated with the GSMA and affected manufacturers. Their public report says key vendors issued software changes and hardened configurations, while the University of Birmingham account of the work says the changes could benefit future SIM-enabled devices across several industries.

What should change next?

Manufacturers can disable or restrict SIM-originating modem commands that their products do not need, validate every allowed command and treat the SIM as a potentially hostile component. Operators also need strong controls around remote profile management, while long-lived connected products need a reliable route for modem and firmware updates.

Consumers should continue installing phone updates and should treat unexpected loss of service or unexplained network downgrades as reasons to contact their operator. The larger lesson belongs to designers: a component that authenticates a device should not automatically be trusted to control it.

Verified topics and entities

Sources and citations4 sources

Published by

N

NewTqnia Science Desk

An institutional editorial team within NewTqnia

A new version of NewTqnia is ready.