{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"Cracking eSIM: Exposing the Hidden Threats in Next-Gen Mobile Security","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/34ac3d59\"></iframe>","width":"100%","height":180,"duration":1003,"description":"eSIM technology has transformed the way we connect—but has it also introduced new vulnerabilities into the heart of modern telecommunications?\nIn this deep-dive episode, we dissect the security architecture, remote provisioning systems, and critical attack surfaces of embedded SIM (eSIM) technology, now deployed in billions of mobile, consumer, and IoT devices worldwide. While eSIMs offer convenience, flexibility, and integration benefits, a growing body of research reveals severe flaws in their design and implementation—flaws that allow profile hijacking, cloning, and even eavesdropping on private communications.\nWe begin by tracing the evolution of Subscriber Identity Module (SIM) technology into today’s eUICC-based eSIM architecture, reviewing the GSMA’s role in standardizing eSIMs for machine-to-machine (M2M), consumer, and IoT deployments. We unpack the core remote provisioning components, such as SM-SR, SM-DP+, LPA, and IPA, and explain how they interact to enable over-the-air SIM profile installation and switching—technically elegant, but increasingly a security liability.\nThe heart of the episode delves into high-impact vulnerabilities that continue to shake the telecom industry:\nMemory exhaustion attacks that brick eSIMs by orphaning profile containers\nMalicious profile locking that disables switching to other networks\nCloning and profile hijacking, demonstrated in 2025 by researchers who extracted private cryptographic keys from real-world GSMA-certified eUICCs\nUndetected Java app injection, allowing rogue code to be embedded in live profiles\nCritical failures in Java Card VM implementations, enabling type confusion and remote profile manipulation\nWe also discuss the wider systemic implications, including:\nHow attackers cloned an Orange eSIM and hijacked a subscriber’s identity undetected\nWhy “tamper-proof” certification claims are now under scrutiny\nThe limitations of current GSMA security fixes and certification frameworks\nWhy hardware security...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}