nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16257 CVE-2019-16257
CRITICAL
Motorola SIMalliance Toolbox Browser Simjacker Vulnerability
Record summary
CVE-2019-16257 has a selected CVSS score of 9.8 (critical).
Description
Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 11, 2019 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
motorola_firmwareBrowse motorola / motorola_firmware | VulnCheck | Version data not supplied | |
References
2adaptivemobile.com
https://www.adaptivemobile.com/blog/simjacker-next-generation-spying-over-mobile