A Threat That Spans More Than Just Smartphones
On August 11 at 17:00, a report detailing newly uncovered SIM card vulnerabilities was released by researchers from the University of Birmingham and Fuzzware. The team used a tool they created, named CATana, to examine 26 devices—18 smartphones and 8 IoT modules—and presented the results at the USENIX WOOT 2026 conference in Baltimore. The research draws attention to a largely hidden attack surface in modern telecom infrastructure.
The flaws originate in a mobile-standard feature called Proactive SIM. This capability enables a SIM card to dispatch commands, including the AT commands that were created in the 1980s for modem management, directly to the attached modem. Some of the tested devices accepted these commands from the SIM without question. The researchers successfully executed arbitrary code with no action from the user, extracted hardware identifiers, made locked Android smartphones open malicious links, and shifted connections from 4G down to 2G. They could also remotely cut off devices or put them out of operation.
SIM Card Flaws Can Have Serious Consequences
A physical SIM swap is not a prerequisite for carrying out an attack. Malware could find its way onto a SIM through an update, via an operator's remote management systems, or during device production. SIM cards are embedded not only in smartphones but also in industrial routers, electric vehicle charging stations, and connected car platforms.
After being notified, chip manufacturers, device makers, and GSMA started addressing the issues. Some companies have already issued software updates and modified security configurations to defend against harmful AT commands. As one Fuzzware representative put it:
“Hostile SIM cards continue to be a significantly underestimated attack vector.”
In short, SIM card vulnerabilities represent a serious threat that goes well beyond phones to any hardware powered by mobile technology.
These findings reinforce the critical need for upgraded cybersecurity across all mobile-connected environments. Since attacks can target industrial infrastructure, vehicles, and other systems, urgent protective measures are essential. Patching software and tightening security settings are now vital for preventing potential exploits. The situation also brings into question the safety of current mobile standards and their ability to meet contemporary security demands.