Urgent.News

What's breaking now, across thousands of outlets.

Tech

'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers

Standardized SIM command from the modem era lets a hostile card run code inside an EV charger

'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers

Researchers from the University of Birmingham and Fuzzware have discovered that standardized SIM cards can be exploited to hijack smartphones, IoT devices, and even electric vehicle (EV) chargers. The research focuses on a feature called Proactive SIM, which allows a SIM card to push commands to a device. However, a specific command within this feature, known as RUN AT, can enable the SIM to execute commands on the device.

This vulnerability was found in six out of eight cellular modules and three out of 18 handsets tested. Qualcomm has implemented a hardened configuration to disable the interface by default, but no vendor has publicly announced an advisory. To exploit this vulnerability, an attacker must already control the SIM card, which typically requires physical access to the SIM slot.

The researchers demonstrated the attack on a commercial Autel EV charger, successfully executing code driven by SIM card-issued commands. This exploit highlights the potential risks of unattended IoT equipment, as physical swaps to access the SIM tray could be easier than with personal smartphones. Despite the concern, the attack vector is limited due to the need for physical access to the SIM slot.

Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techradar.com →

More in Tech

US says Iranian hackers tried to extort HBO

The Justice Department has unsealed an indictment accusing 17 Iranians of cyber crime and hacking campaigns against the US, one of which was directed at streaming service HBO. According to the indictment, members of the Iran-based Mabna Institute have tried to infiltrate US businesses, institutions and agencies since 2013.

More from Tuesday 18 August →