Major Security Flaw: eSIM Cards Compromised, Millions of Users at Risk
2025-07-09
Security Explorations, a research lab of AG Security Research, has uncovered a critical vulnerability in eSIM technology. They successfully compromised a Kigen eUICC card, extracting the private key for the GSMA consumer certificate. This allows attackers to download arbitrary eSIM profiles from mobile network operators, gaining access to sensitive user data and network keys. The vulnerability exploits previously known Java Card flaws from 2019, proving eSIMs are not as secure as advertised. Millions of users relying on Kigen eSIMs are at risk, highlighting a significant weakness in eSIM architecture.