Your Phone's 5G Connection Is Vulnerable to Bypass, DoS Attacks
ID: 0aa767fd-f951-5e79-bf49-5f0df0903727
STIX ID: report--0aa767fd-f951-5e79-bf49-5f0df0903727
Feed Name: Dark Reading
Penn State researchers will present findings showing that unauthenticated 5G broadcast messages and a mishandled security header in a popular mobile processor let attackers using inexpensive SDR gear deploy fake base stations and bypass AKA authentication to perform MITM, data theft, SMS-based phishing, location tracking, and denial-of-service; the flaws were reported and patched by vendors, but a comprehensive fix (such as PKI for broadcasts) is expensive and not yet widely deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
