Researchers found that a malicious or compromised SIM card can abuse built-in SIM Toolkit features to control some phones and cellular-connected devices, forcing network downgrades, shutting devices down, stealing files, and sometimes executing code. The CATANA research tested 26 devices and found SIM-accessible AT modem commands on 9 of them, including 7 of 8 IoT modems. Google previously patched one related Android issue, CVE-2025-48618, in Android 13 through 16 in December 2025; the broader industry issue is being tracked by GSMA as CVD-2026-0122 and affected vendors named include Oppo, Quectel, Qualcomm, and Semtech.
Why it matters: This matters because the attack can come from the SIM itself, including through compromised carrier administration or supply-chain tampering, and can silently weaken security by forcing devices back to 2G or opening attacker-controlled pages. Organizations using cellular modems and anyone managing Android fleets should verify Android patches, review modem hardening options, and assess whether SIM AT-command access is enabled.
info@thehackernews.com (The Hacker News)
2026.08.11
98% relevant
The article appears to be another report on the same SIM Toolkit-based research, focusing specifically on code execution inside cellular modems used in IoT devices rather than the broader summary covering Android phones, forced 2G downgrade, file theft, and modem compromise.
2026.08.11
100% relevant
This article establishes a distinct new story about malicious SIM-based attacks and SIM Toolkit abuse across Android devices and cellular modems, anchored by CATANA research, Android CVE-2025-48618, and GSMA tracking ID CVD-2026-0122.
← Back to all stories