{
  "id": 1795004,
  "title": "'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers",
  "url": "https://urgent.news/2026/08/18/the-attacks-we-found-only-scratch-the-surface-of-what-is-possible",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-18T20:15:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/the-attacks-we-found-only-scratch-the-surface-of-what-is-possible-experts-say-so-called-proactive-sim-cards-can-hijack-smartphones-iot-devices-and-even-ev-chargers"
  },
  "original_language": "en",
  "account": "Researchers from the University of Birmingham and Fuzzware have discovered that standardized SIM cards can be exploited to hijack smartphones, IoT devices, and even electric vehicle (EV) chargers. The research focuses on a feature called Proactive SIM, which allows a SIM card to push commands to a device. However, a specific command within this feature, known as RUN AT, can enable the SIM to execute commands on the device. This vulnerability was found in six out of eight cellular modules and three out of 18 handsets tested. Qualcomm has implemented a hardened configuration to disable the interface by default, but no vendor has publicly announced an advisory. To exploit this vulnerability, an attacker must already control the SIM card, which typically requires physical access to the SIM slot. The researchers demonstrated the attack on a commercial Autel EV charger, successfully executing code driven by SIM card-issued commands. This exploit highlights the potential risks of unattended IoT equipment, as physical swaps to access the SIM tray could be easier than with personal smartphones. Despite the concern, the attack vector is limited due to the need for physical access to the SIM slot.",
  "summary": "Standardized SIM command from the modem era lets a hostile card run code inside an EV charger",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}