CVE-2019-16256
Summary
| CVE | CVE-2019-16256 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-12 13:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker. |
Risk And Classification
EPSS: 0.049490000 probability, percentile 0.912240000 (date 2026-07-21)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Unknown
Problem Types: NVD-CWE-noinfo
CISA Known Exploited Vulnerability
| Vendor | SIMalliance |
|---|---|
| Product | Toolbox Browser |
| Name | SIMalliance Toolbox Browser Command Injection Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-16256 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Samsung | Samsung | - | All | All | All |
| Hardware | Samsung | Samsung | - | All | All | All |
| Operating System | Samsung | Samsung Firmware | - | All | All | All |
| Operating System | Samsung | Samsung Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Simjacker – Next Generation Spying Over Mobile | Mobile Security News | AdaptiveMobile | MISC | www.adaptivemobile.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.