Critical eSIM Vulnerability Enables Profile Cloning and Mobile Surveillance

Abstract digital illustration depicting a futuristic network or cloud computing environment, with glowing teal and orange icons or nodes representing different applications or services connected by lines or data streams, showcasing the concept of interconnected systems and digital transformation.

Security researchers have disclosed a critical vulnerability in eSIM technology that enables the cloning of eSIM profiles and potential surveillance of mobile communications, representing a significant escalation in telecom security threats amid rising concerns about SIM-based attacks. The exploit specifically targets the Java Card Virtual Machine used in eSIM implementations, potentially undermining the security architecture that has made eSIMs an increasingly popular alternative to physical SIM cards.

Researchers demonstrated the vulnerability by successfully cloning an Orange Poland eSIM profile, which allowed calls and messages to be redirected to an unauthorized device. The exploit affects certain implementations including Kigen cards, though its impact may extend to other mobile network operators. The discovery raises particular concern as eSIM adoption continues to grow, with major telecommunications providers worldwide increasingly adopting GSMA-accredited eUICC technology for secure cellular connectivity.

The vulnerability enables multiple attack vectors, including the ability to obtain eSIM profile data used for network authentication, install undetectable backdoors on eSIM chips, and potentially render eSIM cards inoperable. During testing, researchers reported damaging five eSIM cards while exploring the exploit. The development challenges the security assumptions of eSIM technology, which has been widely adopted for its supposed enhanced security features compared to traditional SIM cards.

Security Explorations, which discovered and disclosed the vulnerability, has developed specialized tools to detect vulnerable Java Card VM implementations and extract necessary keys for exploitation. The firm noted that custom methods may be required for different eUICC card types, highlighting the complexity of eSIM security across various implementations.

“The attacker can obtain eSIM profile data… which can be leveraged by well-resourced threat actors to eavesdrop on communications,” said Security Explorations researcher Piotr Gowdiak.

The security firm has criticized Oracle’s response to related vulnerabilities reported in 2019, suggesting that addressing earlier issues might have prevented the current exploit. Oracle has reportedly shown limited concern about the new research findings, despite the growing industry focus on enhanced eSIM security measures, including quantum-resistant implementations.

Mobile industry stakeholders are aware of the vulnerability and are developing mitigation strategies, though specific responses from operators and vendors have not been publicly detailed. The situation emerges as the industry continues to expand eSIM implementations across various devices and use cases, from smartphones to connected cars and IoT devices.

Sources: SecurityWeek, Morningstar Security