HomeSecurityO2 UK fixes user location leak bug

O2 UK fixes user location leak bug

A flaw in O2 UK 's implementation of VoLTE and WiFi Calling technologies could allow a person's general location and other identifying indicators to be leaked simply by calling the target.

See also: New Chrome vulnerability allows data leakage

O2 UK location leak

The issue was discovered by security researcher Daniel Williams. The flaw is estimated to have existed on O2 UK's network since February 2023 and was patched yesterday.

O2 UK is a telecommunications service in the United Kingdom, owned by Virgin Media O2. As of March 2025, the company reported serving nearly 23 million mobile subscribers and 5.8 million broadband in the United Kingdom, making it one of the country's major providers. In March 2017, the company introduced its IP Multimedia Subsystem (IMS), branded as "4G Calling", offering improved audio quality and line reliability during calls.

However, as Williams discovered when analyzing the data traffic during such a call, the signaling messages (SIP Headers) exchanged between the two parties are excessively detailed and revealing, including information such as IMSI, IMEI , and data about the connecting cell.

See also: Twilio denies breach and Steam password leak

Using the Network Signal Guru (NSG) app on a rooted Google Pixel 8 , Williams intercepted the raw IMS signaling messages exchanged during a call and decoded the Cell ID to identify the last cell tower the call recipient had connected to.

O2 UK fixes user location leak bug
O2 UK fixes user location leak bug

Then, he leveraged publicly available tools with cell phone antenna maps to locate the geographic coordinates of the specific antenna. In urban areas where antenna density is high, accuracy can be as low as 100 square meters. In rural areas, geolocation is less accurate, but can still reveal critical information about the target.

Williams found that the method works even when the target is abroad, as he was able to track down a person in Copenhagen, Denmark.

Williams says he contacted O2 UK repeatedly on March 26 and 27, 2025 to report his findings, but received no response. Finally, this morning he received immediate confirmation from O2 UK that the issue had been resolved, which he confirmed through testing.

See also: LockBit ransomware group suffered a serious data leak

An interesting and worrying element that emerges from the above case is how vulnerable even advanced technologies such as VoLTE and WiFi Calling can be if not implemented with strict security measures. While these services offer better sound quality and call reliability, the O2 UK case shows that signaling protocols (SIP) can reveal sensitive data — such as a user’s location or their device’s unique identification numbers (IMSI, IMEI) — to third parties with the right equipment.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS