A malicious SIM card can now take over an EV charger.
Researchers from the University of Birmingham and German security firm Fuzzware built a toolkit called CATana to test whether a standardized feature called Proactive SIM, which lets a SIM push commands to a device, could be abused. They tested 26 devices, 18 phones and eight cellular modules, and found the exploitable command, called RUN AT, exposed on nine of them: three phones (Oppo Find X5, Oppo Reno 14 F 5G, Asus Zenfone 9) and six of eight modules. Using it, they achieved code execution on a commercial Autel EV charger, driven entirely by SIM-issued commands. All nine vulnerable devices ran a Qualcomm chip or modem, though five other Qualcomm-based devices tested were not affected.
The exposure is concentrated in machine-to-machine hardware, EV chargers, industrial routers, car telematics units, rather than smartphones; no iPhone or Pixel was vulnerable. That is also the equipment least likely to ever get a firmware update. Qualcomm has built a hardened configuration that disables the vulnerable interface, and researchers say it will become the default configuration on future devices, though it is not yet deployed across existing hardware, and no vendor has issued a public advisory yet.
The catch that keeps this from being the next Simjacker: it requires physical access to the SIM slot, not just a phone number, and that is exactly the kind of access an unattended charging station or industrial router tends to offer.