Vulnerability record · CVE-2019-16256 · published 12 September 2019
CVE-2019-16256: Samsung devices S@T Browser command injection via SMS (Simjacker)
Trustedconnectivityalliance · S\@T Browser
Some Samsung devices ship the SIMalliance Toolbox Browser (S@T Browser) on the UICC, which can be driven by SIM Toolkit (STK) instructions embedded in an SMS message. This lets a remote sender trigger commands on the device without the user noticing, exposing location and IMEI data or other information. It matters because the attack path is the cellular messaging channel itself, not an app or network service the user controls.
Description
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and confirmed exploitation in CISA KEV.
What it is
Some Samsung devices ship the SIMalliance Toolbox Browser (S@T Browser) on the UICC, which can be driven by SIM Toolkit (STK) instructions embedded in an SMS message. This lets a remote sender trigger commands on the device without the user noticing, exposing location and IMEI data or other information. It matters because the attack path is the cellular messaging channel itself, not an app or network service the user controls.
Impact
An attacker can retrieve location and IMEI information and other data, or execute certain commands on the device. That enables covert tracking and data exfiltration against affected subscribers.
Attack surface
Reached remotely over the cellular network by sending an SMS containing STK instructions to the UICC; the CVSS vector shows network reachability with no privileges and no user interaction. No authentication is required on the attacker side.
Exploitation
Listed in CISA KEV since 2021-11-03, indicating known exploitation in the wild. EPSS 30-day probability is about 4.9 percent (91.7th percentile), and references are tagged Exploit and Third Party Advisory.
What to do
- Apply vendor and carrier updates per vendor instructions, as required by the CISA KEV entry.
- Work with mobile carriers and UICC/eSIM providers to disable or restrict the S@T Browser on affected SIM profiles.
- Inventory affected Samsung device models and SIM profiles, and track vendor/carrier remediation guidance.
- Where the S@T Browser cannot be disabled, consider compensating controls such as SMS filtering at the carrier level.
Detection
- Monitor for anomalous or unexpected STK/S@T Browser activity on UICC or device management telemetry.
- Watch for SMS messages carrying SIM Toolkit instructions, especially from unusual or spoofed senders.
- Alert on unexpected location or IMEI data requests or transmissions originating from mobile devices.
- Correlate carrier SMS gateway logs with device-side SIM Toolkit events for signs of Simjacker-style probing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-16256 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SIMalliance Toolbox Browser Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.adaptivemobile.com/blog/simjacker-next-generation-spying-over-mobile | ExploitThird Party Advisory |
| https://www.adaptivemobile.com/blog/simjacker-next-generation-spying-over-mobile | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-16256 | US Government Resource |
Track CVE-2019-16256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2019-16256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.