The Hidden Danger Inside Your SIM Card: How Researchers Found a New Attack Surface Affecting Billions of Devices
Researchers from the University of Birmingham and Fuzzware developed the CATana toolkit and uncovered that a malicious SIM card can issue low level AT commands to a device's modem through the Proactive SIM feature, en... In tests on 26 devices (18 smartphones and 8 IoT modules), the team demonstrated attacks includi...
Published byEdited with DeepSeek-V4-FlashImages generated with GPT Image 1.5
Researchers from the University of Birmingham and Fuzzware developed the CATana toolkit and uncovered that a malicious SIM card can issue low level AT commands to a device's modem through the Proactive SIM feature, en...
In tests on 26 devices (18 smartphones and 8 IoT modules), the team demonstrated attacks including data exfiltration, forced 2G network downgrades, device shutdown, and zero interaction website openings on locked Andr...
The vulnerabilities are tracked as CVE 2025 48618, CVE 2026 57550, and CVD 2026 0122, with key manufacturers releasing software updates and GSMA coordinating the disclosure process.
What new attack surface did researchers from the University of Birmingham and Fuzzware uncover by developing the CATana toolkit, which devicIllustration of the SIM-based attack vector uncovered by the CATana research, showing how a compromised SIM can issue commands to a variety of connected devices.
AI Prompt
Create a landscape editorial hero image for this Studio Global article: What new attack surface did researchers from the University of Birmingham and Fuzzware uncover by developing the CATana toolkit, which devic. Article summary: Now let me get the specific CVE/tracking details and any additional remediation informationHere is a comprehensive breakdown of the CATana research findings, announced on August 10, 2026.. Topic tags: general, government, education, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
openai.com
A team of researchers from the University of Birmingham and Fuzzware has uncovered a widespread security issue that turns a legitimate cellular standard feature into a weapon. By developing the CATana toolkit, they demonstrated that a compromised SIM card can issue low-level commands directly to a device's modem — commands that can hijack smartphones, connected cars, EV chargers, and industrial equipment silently and without user interaction .
Presented at the 2026 USENIX WOOT Conference on Offensive Technologies in Baltimore, the research reveals what the team calls "specification-compliant attacks" — exploits that work within the official cellular standards .
Studio Global AI
Continue your research
This page includes a source-backed answer you can continue inside Studio Global.
What is the short answer to "The Hidden Danger Inside Your SIM Card: How Researchers Found a New Attack Surface Affecting Billions of Devices"?
Researchers from the University of Birmingham and Fuzzware developed the CATana toolkit and uncovered that a malicious SIM card can issue low level AT commands to a device's modem through the Proactive SIM feature, en...
What are the key points to validate first?
Researchers from the University of Birmingham and Fuzzware developed the CATana toolkit and uncovered that a malicious SIM card can issue low level AT commands to a device's modem through the Proactive SIM feature, en... In tests on 26 devices (18 smartphones and 8 IoT modules), the team demonstrated attacks including data exfiltration, forced 2G network downgrades, device shutdown, and zero interaction website openings on locked Andr...
What should I do next in practice?
The vulnerabilities are tracked as CVE 2025 48618, CVE 2026 57550, and CVD 2026 0122, with key manufacturers releasing software updates and GSMA coordinating the disclosure process.
The core of the problem is the Proactive SIM feature, a longstanding cellular specification that allows a SIM card to send commands directly to the device's modem. One specific command, RUN AT, lets the SIM issue AT commands — the same modem control instructions used since the 1980s — to the mobile equipment (ME) completely without the user's knowledge .
While this feature was designed for legitimate purposes like operator services, the researchers found that very few real-world use cases remain active. Yet almost every device they tested still accepts these commands by default .
Affected Devices: From Smartphones to EV Chargers
The team tested 26 representative devices — 18 smartphones and 8 cellular-connected IoT modules — and found widespread vulnerability across multiple manufacturers and operating systems . The affected IoT modules included devices embedded in:
Electric vehicle (EV) chargers
Industrial equipment
Connected cars and vehicles
The research notes that devices from multiple manufacturers and operating systems were found to support SIM-originating AT commands despite few remaining legitimate use cases .
Attacks Demonstrated: What a Malicious SIM Can Do
Using CATana, the researchers demonstrated that a malicious (or compromised) SIM card could execute the following attacks via the SIM AT interface :
Re-enable closed-down debug interfaces on the device
Exfiltrate sensitive information, including the device's unique IMEI
Send SMS messages or initiate calls without user consent
Obtain arbitrary command execution on the victim's communication processor (baseband)
Force a network downgrade from secure 4G (LTE) to older, less secure 2G
Shut down the victim device entirely
Disable cellular communications altogether
On recent Android devices, force the phone to open an attacker-controlled website with no user interaction, even when the phone was locked
Additional findings included privacy leaks, corrupted baseband memories, and lockscreen bypasses.
How an Attacker Gets a Hostile SIM Card
The research outlines four distinct scenarios through which an attacker could obtain a hostile SIM, each with real-world precedent :
Remote attackers exploiting vulnerabilities in SIM software (applets) to install malicious code over the air
Physical attackers who replace a victim's SIM card or install a thin hardware implant (SIM interposer) — a commercially available layer often sold for carrier unlocking that can be planted in seconds
Compromised operators who abuse remote SIM management features, including eSIM provisioning
Supply-chain attackers who modify SIMs during manufacturing or distribution before they reach end users
Industry Response and Remediation
The researchers coordinated disclosure with the GSM Association (GSMA) and affected chip and device manufacturers before publishing the findings . The industry response was positive: reports were treated seriously, and key manufacturers made software updates and hardened configurations available to customers .
The vulnerabilities identified by the CATana research are tracked under:
CVE-2025-48618
CVE-2026-57550
CVD-2026-0122
Notably, CVE-2026-0122 is listed in the March 2026 Pixel Update Bulletin as a Critical baseband vulnerability capable of remote code execution .
Dr. Marius Muench of the University of Birmingham noted that the resulting mitigations "will benefit billions of future SIM-enabled devices operating worldwide, including smartphones, connected vehicles, payment terminals, routers, critical infrastructure and EV charging systems" .
The Bigger Picture: A Class of Risks, Not a Single Bug
The CATana research builds on earlier work from the same team, including the SIMURAI platform, which demonstrated that SIM card attacks are not one-off vulnerabilities but a class of risks that can be understood across three attack surfaces: physical access, hostile SIM, and baseband firmware bugs .
The CATana toolkit is open-source and designed to help security researchers and device manufacturers systematically test for these SIM-originating AT command vulnerabilities, lowering the barrier to entry for future security research .
pure-oai.bham.ac.uk
Slicing Through the Complexity of SIM Card Security Research