CVE-2019-16256, known as Simjacker, is a critical vulnerability affecting Samsung devices that include the SIMalliance Toolbox Browser (S@T Browser) on the UICC. This flaw allows remote attackers to retrieve sensitive information like location and IMEI, or execute commands, through specially crafted SMS messages containing SIM Toolkit instructions. With a CVSS score of 9.8 (CRITICAL), it poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability has been actively exploited in the wild, as indicated by its inclusion in the KEV catalog, and has garnered considerable community discussion despite a lack of public exploit code or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:trustedconnectivityalliance:s\@t_browser:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.