Security researchers discover SIM card vulnerabilities in mobiles, EV chargers

Security researchers discover SIM card vulnerabilities in mobiles, EV chargers

We treat SIM cards like harmless chips, but they are fully functioning mini-computers. And right now, it could be working against you. At the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore, cybersecurity researchers from the University of Birmingham and security firm Fuzzware revealed that malicious or compromised Subscriber Identity Module (SIM) cards pose severe, overlooked security risks to cellular devices. It could quietly hijack phones, electric vehicle chargers, and critical industrial equipment. Using a custom tool named CATana, the researchers tested 26 representative devices including smartphones and IoT modules used in electric vehicle chargers, connected cars, and industrial equipment. Various manufacturers and operating systems were included. “The fascinating part here is that the proactive capabilities of a SIM and the resulting attack surface is explicitly defined in the technical specifications for cellular communication, resulting into ‘specification-compliant’ attacks,” said Dr Marius Muench, Assistant Professor in Computer Science at the University of Birmingham. The feature flaw The flaw isn’t a coding glitch, but a feature. A built-in feature known as “Proactive SIM” allows a SIM card to issue commands directly to a device’s modem. Among these capabilities sits a powerful relic: AT commands. Created in the 1980s to control dial-up modems, AT commands act as a skeleton key to a device’s cellular hardware. When a SIM issues these instructions, the modem simply obeys. To prove how dangerous this legacy setup is, the research team developed an analysis toolkit called CATana. They put 26 real-world devices to the test, spanning 18 consumer smartphones and eight cellular IoT modules embedded in connected cars and EV charging stations. After confirming that several test devices processed SIM-originated AT commands, the CATana toolkit exposed severe security flaws in the resulting interface. Researchers gained silent, total control over devices without any user interaction simply by exploiting the SIM-to-modem interface. Surprisingly, they were able to execute arbitrary code, steal sensitive hardware identifiers, force locked Android phones to open malicious links, downgrade connection security from 4G to vulnerable 2G networks, and remotely disconnect or shut down the devices entirely. Unseen entry points Smartphones aren’t the only target. The threat is arguably far worse for the internet-connected infrastructure powering our cities. Industrial routers, EV chargers, and automated vehicle systems are deliberately designed like fortresses. Engineers lock down external USB ports and block remote software entry. Yet, almost all of them leave a gaping backdoor wide open: the SIM slot. An attacker doesn’t always need physical access to swap a SIM card, either. Hostile SIMs can enter the wild through infected SIM software updates, rogue cellular operators abusing remote management platforms, or supply-chain tampering during manufacturing. “Hostile SIMs are an overlooked attack vector,” said Kristian Covic of Fuzzware. After discreetly sharing their findings with affected chip manufacturers, device vendors, and the GSMA, key players began rolling out software updates and hardened configurations to neutralize rogue AT commands. While cybersecurity experts and leaked documents have long exposed the dangers of hostile SIM cards, these risks remain largely unmitigated because SIMs are rarely factored into standard security threat models. However, researchers note that industry awareness is finally beginning to shift toward addressing this overlooked vulnerability. Until those updates reach every smartphone and smart charger on Earth, the tiny chip inside your phone remains a reminder: in cybersecurity, absolute trust is the ultimate vulnerability. Recommended ArticlesGet the latest in engineering, tech, space & science - delivered daily to your inbox.Mrigakshi is a science journalist who enjoys writing about space exploration, biology, and technological innovations. Her work has been featured in well-known publications including Nature India, Supercluster, The Weather Channel and Astronomy magazine. If you have pitches in mind, please do not hesitate to email her.

Original Source

Read the full article at Interestingengineering →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.