Executive brief
The SIMalliance Toolbox Browser (S@T Browser) on certain UICCs, notably in Samsung devices, contains a command injection vulnerability known as Simjacker. Remote attackers can execute SIM Toolkit (STK) instructions via specially crafted SMS messages to retrieve sensitive location and IMEI information or execute other unauthorized commands.
Affected products
- Trusted Connectivity Alliance S@T Browser (SIMalliance Toolbox Browser) -
- Samsung Samsung Devices -
Timeline
- 2019-09-12: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2019-09-12: exploited: Simjacker attack reported as exploited in the wild.