CVE-2019-16256
KEV PoC massSimjacker: STK Command Injection in SIMalliance Toolbox (S@T) Browser
CISA: SIMalliance Toolbox Browser Command Injection Vulnerability
CVE-2019-16256 (Simjacker) is a command injection flaw in the SIMalliance Toolbox Browser (S@T Browser), an applet embedded on the UICC (SIM card) of some Samsung devices. A remote attacker can trigger it unauthenticated and without user interaction by sending a specially crafted SMS message containing SIM Toolkit (STK) instructions that the S@T Browser mishandles. Successful abuse lets the attacker retrieve the device's location and IMEI, retrieve other data, or execute certain commands on the affected device. Affected deployments are SIM cards carrying the S@T Browser applet, which per CISA data affect some Samsung devices. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known in-the-wild exploitation, and EPSS assigns a 4.9% probability of exploitation within 30 days (92nd percentile).
What to do: Remediation is carrier-side, not handset-side: coordinate with your mobile operators/SIM vendors to have the S@T Browser patched or disabled via over-the-air SIM applet updates or SIM replacement, per vendor instructions as required by the CISA KEV listing. Enterprises should check device fleets with their carriers to confirm whether issued SIMs include the S@T Browser, and be aware that crafted SMS can silently trigger location/IMEI retrieval with no visible user interaction. Where feasible, request carrier-level filtering of anomalous SIM Toolkit SMS commands as a mitigation.
| Trusted Connectivity Alliance (SIMalliance) SIMalliance Toolbox Browser (S@T Browser) | — |
| Samsung Devices whose UICC includes the S@T Browser applet | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
- Affected
- SIMalliance Toolbox Browser
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trustedconnectivityalliance
- Products
- s\@t browser
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.