The Latest in IT Security

USSD Exploit Can Lock All Android Phone SIM Cards

02
Oct
2012

While only a certain brand of smartphones was vulnerable to being wiped via an USSD command embedded in webpages, the locking of SIM cards is possible with most any Android phone.

The victim just needs to have the phone access a maliciously-formed “tel:” URI, such as by visiting a web page with an embedded iframe. When the mobile browser loads it, the embedded USSD command (in this case, the PIN or PUK change command) is executed, without need for confirmation from the user.

After a number of attempts using the wrong PUK, the SIM card is locked and requires a new PUK number to be re-activated.

We strongly recommend that Android users install Bitdefender USSD Wipe Stopper, which has been updated to reflect this threat scenario.

Leave a reply


Categories

SATURDAY, APRIL 20, 2024
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments