While this feature was designed for legitimate purposes like operator services, the researchers found that very few real-world use cases remain active. Yet almost every device they tested still accepts these commands by default .
The team tested 26 representative devices — 18 smartphones and 8 cellular-connected IoT modules — and found widespread vulnerability across multiple manufacturers and operating systems . The affected IoT modules included devices embedded in:
The research notes that devices from multiple manufacturers and operating systems were found to support SIM-originating AT commands despite few remaining legitimate use cases .
Using CATana, the researchers demonstrated that a malicious (or compromised) SIM card could execute the following attacks via the SIM AT interface :
The research outlines four distinct scenarios through which an attacker could obtain a hostile SIM, each with real-world precedent :
The researchers coordinated disclosure with the GSM Association (GSMA) and affected chip and device manufacturers before publishing the findings . The industry response was positive: reports were treated seriously, and key manufacturers made software updates and hardened configurations available to customers
.
The vulnerabilities identified by the CATana research are tracked under:
Notably, CVE-2026-0122 is listed in the March 2026 Pixel Update Bulletin as a Critical baseband vulnerability capable of remote code execution .
Dr. Marius Muench of the University of Birmingham noted that the resulting mitigations "will benefit billions of future SIM-enabled devices operating worldwide, including smartphones, connected vehicles, payment terminals, routers, critical infrastructure and EV charging systems" .
The CATana research builds on earlier work from the same team, including the SIMURAI platform, which demonstrated that SIM card attacks are not one-off vulnerabilities but a class of risks that can be understood across three attack surfaces: physical access, hostile SIM, and baseband firmware bugs .