University of Birmingham Researchers Uncover Critical SIM Vulnerability Enabling Remote Device Takeover
This digest was compiled by AI from multiple sources — links to the originals are below.

Security researchers from the University of Birmingham and Fuzzware have discovered a critical SIM card vulnerability that allows attackers to remotely take control of devices. The flaw, found in 26 smartphones and industrial cellular modules, leverages legacy AT commands from the 1980s to execute unauthorized actions without user interaction.
The SIM Flaw
Researchers used a custom analysis tool called CATana to examine 26 devices, including 18 smartphones and 8 industrial IoT modules. They traced the vulnerability to the 'Proactive SIM' feature, a standard that processes AT commands dating to the 1980s. This feature enables SIM cards to send commands directly to the device's modem without authorization. The flaw is brand-independent and affects any device using the cellular modem standard.
Remote Exploitation
Attackers can exploit the vulnerability without any user interaction. By sending malicious network updates or compromising the supply chain, they can redirect locked devices to harmful websites, downgrade network connections from 4G to less secure 2G, or disable the device entirely. Physical access to the SIM card is not required, making the attack vector broadly accessible.
Industry Response
Following notification by the researchers, industry body GSMA and hardware manufacturers have begun developing urgent security patches. The updates aim to block malicious commands transmitted via the Proactive SIM feature. No timeline for the patches has been disclosed, though the flaw affects a wide range of connected devices beyond smartphones, including electric vehicle chargers.
What's Next
GSMA is expected to coordinate the release of security patches through hardware manufacturers and network operators in the coming weeks. However, it remains unclear how long it will take to secure billions of SIM cards worldwide, and whether the vulnerability has already been exploited in the wild.
2 sources
University of Birmingham Researchers Uncover Critical SIM Vulnerability Enabling Remote Device Takeover



