← Vulnerability feed

Vulnerability record · CVE-2019-16256 · published 12 September 2019

CVE-2019-16256: Samsung devices S@T Browser command injection via SMS (Simjacker)

Trustedconnectivityalliance · S\@T Browser

Some Samsung devices ship the SIMalliance Toolbox Browser (S@T Browser) on the UICC, which can be driven by SIM Toolkit (STK) instructions embedded in an SMS message. This lets a remote sender trigger commands on the device without the user noticing, exposing location and IMEI data or other information. It matters because the attack path is the cellular messaging channel itself, not an app or network service the user controls.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 4.9% · top 8.1%
9.8CVSS 3.1 base score, v2 7.5
4.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication, no user interaction, and confirmed exploitation in CISA KEV.

What it is

Some Samsung devices ship the SIMalliance Toolbox Browser (S@T Browser) on the UICC, which can be driven by SIM Toolkit (STK) instructions embedded in an SMS message. This lets a remote sender trigger commands on the device without the user noticing, exposing location and IMEI data or other information. It matters because the attack path is the cellular messaging channel itself, not an app or network service the user controls.

Impact

An attacker can retrieve location and IMEI information and other data, or execute certain commands on the device. That enables covert tracking and data exfiltration against affected subscribers.

Attack surface

Reached remotely over the cellular network by sending an SMS containing STK instructions to the UICC; the CVSS vector shows network reachability with no privileges and no user interaction. No authentication is required on the attacker side.

Exploitation

Listed in CISA KEV since 2021-11-03, indicating known exploitation in the wild. EPSS 30-day probability is about 4.9 percent (91.7th percentile), and references are tagged Exploit and Third Party Advisory.

What to do

  • Apply vendor and carrier updates per vendor instructions, as required by the CISA KEV entry.
  • Work with mobile carriers and UICC/eSIM providers to disable or restrict the S@T Browser on affected SIM profiles.
  • Inventory affected Samsung device models and SIM profiles, and track vendor/carrier remediation guidance.
  • Where the S@T Browser cannot be disabled, consider compensating controls such as SMS filtering at the carrier level.

Detection

  • Monitor for anomalous or unexpected STK/S@T Browser activity on UICC or device management telemetry.
  • Watch for SMS messages carrying SIM Toolkit instructions, especially from unusual or spoofed senders.
  • Alert on unexpected location or IMEI data requests or transmissions originating from mobile devices.
  • Correlate carrier SMS gateway logs with device-side SIM Toolkit events for signs of Simjacker-style probing.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-16256 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SIMalliance Toolbox Browser Command Injection Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-16256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2019-16256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.