ELSEIF
Your brief EB
312 stories from 93 feeds 198 clusters Refreshed 23 seconds ago next pull 11:36

AI Signal 445

Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

Standards-defined SIM functionality can be weaponized to execute code, exfiltrate files, force 2G fallback, and remotely disable devices.

WHY IT MATTERS

Engineers building or operating cellular-connected devices must now treat the SIM as an untrusted input. Any device that exposes AT commands to the SIM is effectively running a second, unauthenticated control plane. The attacks are specification-compliant, so patching individual bugs will not close the entire surface.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

A malicious SIM can issue AT commands to the host modem, enabling code execution, file theft, and forced 2G fallback.

02

Nine of 26 tested devices exposed the AT interface to the SIM; IoT modems were far more likely to be vulnerable than smartphones.

03

The GSMA is tracking the issue, but the only long-term fix is to deprecate the RUN AT capability in the cellular standards.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G Open ↗