HomeSecurityeSIM vulnerability in Kigen's eUICC cards exposes IoT devices

eSIM vulnerability in Kigen's eUICC cards exposes IoT devices

Cybersecurity researchers have discovered a new hacking technique that exploits vulnerabilities in eSIM technology, which is used in modern smartphones, exposing users to serious risks.

See also: Google plans SIM backup

eSIM vulnerability

The issues are traced to the Kigen eUICC card. According to the Irish company's website, more than two billion SIMs in IoT devices had been activated by December 2020.

The findings come from Security Explorations, a research lab of AG Security Research. Kigen awarded the company a $30,000 for reporting them.

An eSIM, or embedded SIM, is a digital SIM card that is embedded directly into the device as software installed on an integrated circuit (eUICC). eSIMs allow users to activate a mobile phone plan without the need for a physical SIM card. The eUICC software offers features such as carrier profile switching, remote management, and SIM profile configuration.

According to a statement from Kigen, the vulnerability is located in the GSMA TS.48 Generic Test Profile, version 6.0 and earlier, which is reportedly used in eSIM products for radio standards compliance testing.

See also: Google Fi has detected faulty SIM cards

Specifically, the issue allows the installation of unverified and potentially malicious applets. GSMA TS.48 v7.0, released last month, resolves the issue by restricting the use of this test profile. All previous versions of the TS.48 specification have now been retired.

eSIM vulnerability in Kigen's eUICC cards exposes IoT devices
eSIM vulnerability in Kigen's eUICC cards exposes IoT devices

Additionally, the vulnerability could facilitate the extraction of the Kigen eUICC identity certificate, thus allowing the capture of arbitrary profiles from mobile network operators (MNOs) in plain text, access to confidential MNO information, and forge profiles for insertion into any eUICC without being detected by the operator.

Security Explorations said the findings build on its previous research from 2019, which had uncovered multiple security vulnerabilities in Oracle Java Card technology that could allow a permanent backdoor to be installed on the card. One of these vulnerabilities also affected Gemalto SIM cards, which are based on Java Card technology.

See also: Android's eSIM portability now works with more smartphone brands

These vulnerabilities can be exploited to “ compromise Java Card virtual machine memory security ” and gain full access to the card’s memory, breach the firewall between applets, and potentially achieve native code execution. While these attacks may seem difficult to implement, they are actually entirely feasible for capable, state-backed groups. Attackers could compromise an eSIM and install an invisible backdoor , allowing all communications to be monitored and intercepted

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS