- Researchers discover a standardized SIM command is uncovered on 9 of 26 examined units and used it to succeed in code execution on a business EV charger
- The publicity is focused in machine-to-machine {hardware} relatively than telephones, affecting six of 8 mobile modules however best 3 of 18 handsets, with out a iPhone or Pixel amongst them
- Every assault calls for the attacker to already keep an eye on the SIM, and whilst Qualcomm has produced a hardened configuration disabling the interface via default, no dealer had revealed a public advisory but
A malicious SIM card can instruct the software it sits in to run instructions of an attacker’s opting for, and at the mobile modules embedded in electrical automobile chargers, commercial routers, and automobile telematics gadgets, necessarily permitting it to take all of the software over.
Researchers from the University of Birmingham and the German safety company Fuzzware demonstrated this in opposition to a business Autel EV charger, reaching code execution pushed fully SIM card-issued instructions.
One malicious SIM card to rule all of them?
The paintings makes a speciality of a standardized characteristic known as Proactive SIM, which as a characteristic, isn’t malicious; it is a same old in a mobile specification that shall we a SIM push instructions to a tool relatively than appearing as a passive identifier for one’s identification on a community.
The downside is one particular command in that set, RUN AT, which asks the modem to execute an AT command, the modem keep an eye on language relationship to the 1981 Hayes Smartmodem that each and every dealer has since prolonged with its personal additions.
The toughen extender necessarily offers a SIM module its personal general-purpose console on units that lack safeguards to forestall such an assault.
Tomasz Piotr Lisowski and Dr Marius Muench of Birmingham, operating with Fuzzware’s Kristian Covic, constructed a toolkit known as CATana to determine what a adversarial card may do with that console.
The staff tested 26 devices, 18 smartphones and 8 mobile modules, and located the SIM AT interface uncovered on 9 of them. The publicity is overwhelmingly concentrated in machine-to-machine {hardware}: six of the 8 modules authorised the command, in comparison with simply 3 of the 18 telephones: the Oppo Find X5, the Oppo Reno 14 F 5G, and the Asus Zenfone 9. This makes it no longer precisely a Simjacker-esque exploit however nonetheless person who must be taken severely.
All 9 units that authorised the command run a Qualcomm chip or modem, however 5 others that do weren’t prone to the assault. The researchers first shared the experiences with Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, and with the GSMA in May. Qualcomm has since constructed a hardened configuration that switches the interface off via default, which the researchers say would be the default on long run units.
The assault vector, on the other hand, is proscribed as a result of, to leverage it, the attacker will have to already keep an eye on the SIM itself. Knowing a sufferer’s touch quantity isn’t sufficient; the attacker wishes bodily get right of entry to to the SIM slot. The exploit is actual and relating to, but it surely has restricted software in comparison to a far off one for smartphones.
The IoT facet is extra relating to, on the other hand: unattended apparatus with an obtainable SIM tray can now doubtlessly be exploited, and bodily swaps may well be more uncomplicated than with one thing extra private, like one’s private telephone. The card necessarily talks to the similar of a Linux pc, person who the paper calls a wealthy assault floor for adversarial SIM playing cards.
For now, the irony is that whilst fashionable smartphones have in large part retired the outside this assault vector exploits, the machine-to-machine international has no longer, and the apparatus least prone to obtain a firmware replace is the apparatus maximum uncovered lately.
Follow TechRadar on Google News and add us as a preferred source to get our knowledgeable information, opinions, and opinion on your feeds.
Source: www.techradar.com



