ZeroHour

CVE-2019-16256

KEV PoC mass

Simjacker: STK Command Injection in SIMalliance Toolbox (S@T) Browser

CISA: SIMalliance Toolbox Browser Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2019-16256 (Simjacker) is a command injection flaw in the SIMalliance Toolbox Browser (S@T Browser), an applet embedded on the UICC (SIM card) of some Samsung devices. A remote attacker can trigger it unauthenticated and without user interaction by sending a specially crafted SMS message containing SIM Toolkit (STK) instructions that the S@T Browser mishandles. Successful abuse lets the attacker retrieve the device's location and IMEI, retrieve other data, or execute certain commands on the affected device. Affected deployments are SIM cards carrying the S@T Browser applet, which per CISA data affect some Samsung devices. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known in-the-wild exploitation, and EPSS assigns a 4.9% probability of exploitation within 30 days (92nd percentile).

What to do: Remediation is carrier-side, not handset-side: coordinate with your mobile operators/SIM vendors to have the S@T Browser patched or disabled via over-the-air SIM applet updates or SIM replacement, per vendor instructions as required by the CISA KEV listing. Enterprises should check device fleets with their carriers to confirm whether issued SIMs include the S@T Browser, and be aware that crafted SMS can silently trigger location/IMEI retrieval with no visible user interaction. Where feasible, request carrier-level filtering of anomalous SIM Toolkit SMS commands as a mitigation.

Affected
Trusted Connectivity Alliance (SIMalliance) SIMalliance Toolbox Browser (S@T Browser)
Samsung Devices whose UICC includes the S@T Browser applet
Estimated exposure
masson the order of hundreds of millions to ~1 billion mobile subscribers (SIM cards carrying the S@T Browser) — The referenced AdaptiveMobile Simjacker research assessed the S@T Browser as deployed on SIM cards issued by major mobile operators in dozens of countries, and deployment patterns of carrier-issued SIMs imply a population of roughly a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

CISA Known Exploited Vulnerability
Affected
SIMalliance Toolbox Browser
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trustedconnectivityalliance
Products
s\@t browser
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.