CVE-2019-16256

CRITICAL(9.8)KEV

SIMalliance Toolbox Browser Command Injection Vulnerability

Description

CVE-2019-16256 is a critical-severity command injection vulnerability in the SIMalliance Toolbox Browser (S@T Browser) embedded on UICC SIM cards, widely known as the Simjacker attack. The vulnerability allows remote attackers to send specially crafted SMS messages containing SIM Toolkit (STK) instructions that the S@T Browser executes without user interaction, enabling retrieval of device location data, IMEI numbers, and execution of other commands on the target device. CISA has confirmed active exploitation of this vulnerability by adding it to the Known Exploited Vulnerabilities catalog. With an EPSS score of 61.19% (98.3rd percentile), CVE-2019-16256 presents a significant and ongoing threat to mobile device security worldwide.

KEV Information

Vendor
SIMalliance
Product
Toolbox Browser
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9

Affected Products

VendorProductVersion
trustedconnectivityalliances\@t browser-

Multiple CVSS Assessments

Source: [email protected](Primary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
9.8
CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

Command Injection

Command injection vulnerabilities occur when an application passes unsafe data to a system command interpreter. In the case of CVE-2019-16256, the S@T Browser on SIM cards processes STK commands received via SMS without proper validation or authorization checks, allowing attackers to inject and execute arbitrary commands on the SIM and the host mobile device.

Learn more: Command Injection — MITRE CWE

Impact Analysis

CVE-2019-16256 carries a CVSS 3.1 score of 9.8 (CRITICAL), reflecting the maximum severity of this vulnerability. The attack is network-based and requires no authentication, no user interaction, and no special conditions, making it exploitable by any attacker capable of sending an SMS message. Confidentiality (High): Attackers can retrieve sensitive device information including geographic location, IMEI, and other identifying data. Integrity (High): The vulnerability allows execution of arbitrary STK commands, enabling unauthorized actions on the device such as sending SMS messages, initiating calls, or launching a browser. Availability (High): Repeated exploitation can disrupt normal device operation. The EPSS score of 61.19% confirms a high likelihood of active exploitation, and the scale of impact is enormous given that millions of SIM cards globally may contain the vulnerable S@T Browser.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2019-16256 by listing it in the Known Exploited Vulnerabilities catalog. The Simjacker attack was first disclosed by AdaptiveMobile Security, which documented its use by a surveillance vendor against mobile users in multiple countries, with exploitation details published in their research blog. The EPSS score of 61.19% (98.3rd percentile) indicates a high probability of exploitation activity. The attack requires only the ability to send SMS messages to the target, making the barrier to exploitation extremely low for nation-state actors and sophisticated threat groups with access to SMS infrastructure.

Remediation

  1. Apply updates per vendor instructions as required by CISA KEV. Contact your SIM card provider or mobile network operator to determine if your SIM cards contain the S@T Browser and request updated firmware or replacement SIMs.
  2. Mobile network operators should implement SMS filtering at the network level to detect and block messages containing suspicious STK command payloads targeting the S@T Browser.
  3. Deploy network-level protections that inspect incoming SMS messages for binary SMS payloads containing SIM Toolkit instructions, particularly those targeting the S@T Browser TAR (Toolkit Application Reference).
  4. Organizations should conduct an inventory of deployed SIM cards to identify those running the vulnerable S@T Browser and prioritize replacement with SIMs that do not include this component or that have updated firmware.
  5. Monitor for indicators of Simjacker exploitation, including unusual binary SMS traffic patterns, unexpected device location queries, and anomalous STK activity in mobile device management (MDM) logs.

Technical Details

CVE-2019-16256 targets the S@T Browser (SIMalliance Toolbox Browser), a legacy application embedded on the UICC (Universal Integrated Circuit Card) of certain SIM cards. The S@T Browser processes SIM Toolkit (STK) instructions delivered via specially crafted binary SMS messages. When a malicious SMS containing STK commands reaches a SIM card with the vulnerable S@T Browser, the commands are executed automatically without any notification or confirmation from the device user. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) reflects that the attack is entirely network-based via SMS, requires no complexity or privileges, and results in complete compromise of confidentiality, integrity, and availability. The vulnerability is particularly dangerous because it operates at the SIM card level, below the operating system, making it invisible to mobile security applications and undetectable by the device user.

Frequently Asked Questions

Is CVE-2019-16256 being actively exploited?

Yes. CVE-2019-16256, known as Simjacker, has been actively exploited by surveillance companies targeting mobile users across multiple countries. CISA has confirmed this by listing the vulnerability in its Known Exploited Vulnerabilities catalog. The EPSS score of 61.19% (98.3rd percentile) further indicates high exploitation activity.

What products are affected by CVE-2019-16256?

CVE-2019-16256 affects SIM cards that include the SIMalliance Toolbox Browser (S@T Browser) on the UICC. This includes SIM cards from various manufacturers and mobile operators. Samsung devices were specifically mentioned in the initial disclosure, but any SIM card with the S@T Browser installed may be vulnerable.

How do I fix CVE-2019-16256?

Contact your mobile network operator or SIM card provider to determine if your SIM contains the S@T Browser. Request replacement SIMs without the vulnerable component or with updated firmware. Network operators should implement SMS filtering to block malicious STK command payloads.

How severe is CVE-2019-16256?

CVE-2019-16256 has a CVSS 3.1 score of 9.8 (CRITICAL), the highest severity rating. The vulnerability allows complete remote compromise via SMS without any user interaction. The EPSS percentile of 98.3% places it among the most likely exploited vulnerabilities, and its use in real-world surveillance operations confirms the critical nature of this threat.

CVSS Score

9.8
CRITICAL(9.8)

EPSS Score

EPSS Score4.95%
EPSS Percentile91.5%

Dates

PublishedSeptember 12, 2019
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.