Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
University of Birmingham researchers demonstrated that compromised SIM cards can leverage the Proactive SIM feature to execute arbitrary AT commands on compatible modems, potentially leading to code execution, data theft, or forced network downgrades. Testing revealed vulnerabilities in devices from Qualcomm, Quectel, OPPO, Autel, and ASUS, including a command injection flaw in an AUTEL EV charger using a Quectel module.
The study also identified CVE-2025-48618, which allowed hostile SIMs to launch browser sessions on locked Android phones without user interaction; Google fixed this issue in Android 13 through 16. The team has published a toolkit called CATana and recommends retiring the RUN AT command entirely rather than just patching specific instances, as the underlying specification still permits significant risk.