Critical O2 UK VoLTE Flaw Leaks User Location
2025-05-17
A security researcher discovered a critical vulnerability in O2 UK's VoLTE implementation. IMS signaling messages reveal users' IMSI, IMEI, and cell ID, allowing trivial geolocation. Despite contacting O2, no response or fix has been implemented. This affects all O2 VoLTE users and persists even with VoLTE disabled, as the last connected cell is still revealed.
Tech