Вредоносная SIM-карта может выполнить код на устройстве и похитить данные
Researchers from the University of Birmingham and Fuzzware demonstrated that a compromised SIM card can send AT commands to force arbitrary code execution, file exfiltration, and network degradation on connected devices. The study tested 26 devices using a new toolkit called CATana, finding vulnerabilities in several smartphones including the Oppo Find X5, Oppo Reno 14 F 5G, and Asus Zenfone 9, as well as multiple IoT modulators. Notably, the team achieved code execution on an Autel charging station equipped with a Quectel EC25-AFX module.
The issue stems from standard proactive SIM command specifications allowing RUN AT instructions, which vendors should disable or retire. Related fixes were issued for CVE-2025-48618 (Google) earlier, while current tracking identifiers include CVE-2026-57550 (Qualcomm) and CVD-2026-0122 (GSMA).