Executive brief
Verizon's mobile voice and messaging service (VoLTE) was found to be transmitting control signals without standard encryption and integrity protections. This allows an attacker positioned on the network—such as someone operating a malicious cell tower or a compromised network node—to intercept, listen to, or modify calls and text messages. While Verizon has stated that security updates are being rolled out, many users may remain vulnerable until the network-wide enforcement is complete.
Technical details
The Verizon IMS signaling stack lacks implementation of IPsec integrity protection, specifically missing Security-Client/Security-Server headers and Encapsulating Security Payload (ESP) traffic as required by 3GPP TS 33.203 and GSMA IR.92. This vulnerability allows an on-path attacker (e.g., via a rogue base station or compromised IMS intermediary) to perform passive monitoring or active manipulation of SIP messages. Attackers can intercept plaintext registration, call setup (INVITE), and messaging (MESSAGE) packets to perform call hijacking, SMS spoofing, or denial-of-service via forged BYE/CANCEL messages. While Apple's iOS 26.5 carrier bundle introduced preparatory configuration, network-level enforcement by Verizon is required for full mitigation.
Affected products
- Verizon IMS (IP Multimedia Subsystem) All versions prior to late 2026 updates
Timeline
- 2026-04-30: other: Verizon notified of the vulnerability
- 2026-05-11: other: iOS 26.5 released with preparatory IMS configuration changes
- 2026-06-02: disclosed: Public disclosure of CVE-2026-10629