🔒Malicious SIMs Can Hijack Phones and Downgrade 5G to 2G
Your phone's SIM card could be a backdoor
TL;DR
Researchers found that malicious SIM cards can execute commands on devices, leading to file theft, denial of service, and connection downgrades. Nine out of twenty-six tested devices were vulnerable.
Malicious SIM cards can now hijack phones, steal files, and downgrade 5G connections to 2G. Researchers discovered that the proactive SIM functionality allows a SIM to issue commands to the device it's in, enabling attacks like code execution, file theft, and connection downgrades. This affects Android devices running from version 13 through 16, with Google issuing patches for CVE-2025-48618 in December 2025. Four vulnerabilities were uncovered, impacting 9 out of 26 tested devices, including the Autel EV charger and Oppo Reno14 F 5G.

Key Points
Researchers tested 26 devices, finding that 9 exposed an AT command interface to the SIM card.
Four vulnerabilities were uncovered, including file theft against Quectel EG25-G modems and connection downgrades on Oppo Reno14 F 5G.
Google patched Android versions 13 through 16 for CVE-2025-48618 in December 2025.
Qualcomm produced a hardened configuration that disables the SIM AT interface by default, addressing security concerns.
The GSMA is tracking this issue as CVD-2026-0122.
Why It Matters
If you're running Android 13 through 16, your device might be vulnerable to SIM-based attacks. Google patched CVE-2025-48618 in December 2025, but not all devices have been updated yet. Qualcomm's hardened configuration disables the risky proactive SIM functionality by default, improving security for new devices.
Frequently Asked Questions
Why does this matter?
If you're running Android 13 through 16, your device might be vulnerable to SIM-based attacks. Google patched CVE-2025-48618 in December 2025, but not all devices have been updated yet. Qualcomm's hardened configuration disables the risky proactive SIM functionality by default, improving security for new devices.
What happened?
Researchers found that malicious SIM cards can execute commands on devices, leading to file theft, denial of service, and connection downgrades. Nine out of twenty-six tested devices were vulnerable.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 2,813 builders reading daily.