What's Happening?
Researchers from the University of Birmingham have identified significant security vulnerabilities associated with malicious SIM cards, which can compromise smartphones, EV chargers, and other connected devices. Presented at the 2026 USENIX WOOT Conference,
the study highlights how compromised SIMs can gather device information, interfere with connectivity, and serve as entry points for cyberattacks. The research team developed the CATana toolkit to explore the risks posed by SIM-originating AT commands, discovering multiple security vulnerabilities across various devices. These vulnerabilities allow attackers to execute commands, exfiltrate information, and disrupt device functionality.
Why It's Important?
The findings underscore the critical need for enhanced security measures in the rapidly growing Internet of Things (IoT) ecosystem. As more devices become interconnected, the potential for cyberattacks increases, posing risks to personal privacy and infrastructure security. The study highlights the importance of including hostile SIMs in threat models and the need for manufacturers to address these vulnerabilities. Ensuring the security of connected devices is essential for maintaining consumer trust and safeguarding sensitive information.
What's Next?
The researchers have reached out to the GSM Association and affected manufacturers to address the identified vulnerabilities. Key manufacturers are expected to release software updates and hardened configurations to mitigate these risks. The study calls for a reevaluation of legacy SIM features and the development of more secure communication protocols. As the IoT landscape continues to evolve, ongoing research and collaboration between industry stakeholders will be crucial in addressing emerging security challenges.











