logo

eSIM Bug in Millions of Phones Enables Spying, Takeover

ID: eb363f0a-f2f0-5150-ab13-32c941384bff

STIX ID: report--eb363f0a-f2f0-5150-ab13-32c941384bff

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-07-10

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

A researcher found a Java Card VM "type confusion" vulnerability in Kigen eUICC eSIMs that allowed theft of private keys and over-the-air installation of malicious applets; Kigen published a patch for the affected eSIM OS variant, but because Java Card underpins many eSIM implementations, the flaw could expose large numbers of devices to spying, cloning, and interception of communications—an attractive capability for nation-state actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.