Proactive SIM Card Risks: What Security Pros Need to Know

Vulnerabilities in Proactive SIM commands expose IoT and industrial devices, putting EV chargers and other unattended hardware at risk from attackers with SIM access.

Proactive SIM Card Risks: What Security Pros Need to Know
Andrew Wallace

Andrew Wallace

Professional Tech Editor

Focuses on professional-grade hardware, software, and enterprise solutions.

What Is the Proactive SIM Attack and Who Is at Risk?

Security experts recently uncovered how a standardized SIM card feature, Proactive SIM, can be misused to run commands on devices with vulnerable cellular modules. While the feature itself is intended to let SIMs interact more flexibly with devices, researchers demonstrated that a malicious SIM could exploit this to issue system-level commands—most notably on IoT and industrial equipment such as EV chargers that use embedded cellular modules.

Only devices that expose a specific modem control command—typically via older or less-secure cellular hardware—are vulnerable. In tests, this interface was found open on six of eight IoT/cellular modules but only three of 18 smartphones, none of which were iPhones or Pixel devices. The issue primarily affects unattended connected equipment, like industrial routers and vehicle telematics units, rather than mainstream phones.

How Serious Is the Threat and What Are Its Limits?

Исследователи показали атаку на заблокированный Android через SIM-карту
Исследователи показали атаку на заблокированный Android через SIM-карту

Unlike over-the-air threats, exploiting this vulnerability requires the attacker to already have control over the SIM inside the target device. This significantly limits mass exploitation for consumer handsets. However, for IoT and industrial installations—especially those with externally accessible, rarely monitored SIM slots—risk remains notable. Unattended devices are both easier to access physically and less likely to be updated with security fixes.

For private sector deployments, this means that legacy or poorly maintained hardware may be at increased risk, particularly if the technology stack relies on cellular modules from vendors with exposed Proactive SIM interfaces. Newer Qualcomm configurations address the risk by disabling the vulnerable feature by default, a move expected to improve future device security.

Protecting Devices: What Practical Steps Should Organizations Take?

  • Audit your hardware inventory: Identify connected devices using cellular modules—especially those in unattended roles (e.g., smart meters, industrial gateways, or EV charging stations).
  • Prioritize firmware updates: Where possible, update cellular modules to versions that disable or restrict Proactive SIM command execution.
  • Physically secure SIM slots: For deployed devices, use tamper-evident seals or physical locks to make SIM swapping more difficult.
  • Engage with vendors: Ask solution providers about their mitigation stance and update pathways for exposed modules.
  • Monitor for unusual device activity: Set up alerts for unexpected command execution or device behavior, especially in equipment that should rarely change state on its own.

Key Takeaways for Security Leaders

Security researchers discover SIM card vulnerabilities in mobiles, EV  chargers
Security researchers discover SIM card vulnerabilities in mobiles, EV chargers

Proactive SIM attacks highlight a persistent risk in industrial and IoT deployments: older mobile connectivity standards can still expose new attack surfaces when hardware is left unpatched or physically accessible. While smartphones are largely unaffected by this issue, organizations relying on machine-to-machine cellular infrastructure should review security controls, work with vendors to update devices, and treat unattended SIM-equipped hardware as a latent risk. Practical mitigation focuses on minimizing physical access and ensuring rapid adoption of firmware that closes exposed interfaces.

React to this story

Related Posts