MSU researchers expose cellular lost-device reporting vulnerabilities affecting 4G and 5G
Researchers at Michigan State University have identified six vulnerabilities in cellular lost-device reporting systems that allow attackers to remotely blacklist legitimate devices using their IMEI. These flaws, which affect 4G and 5G networks, could be exploited to disrupt cellular-connected home security systems and new flagship smartphones.
Key Takeaways
- Six vulnerabilities were discovered across mobile devices, carrier reporting infrastructure, and cross-carrier operations like the GSMA Central Equipment Identity Register.
- Two major U.S. home security providers, representing 41% of the market, use cellular IoT modems susceptible to remote freezing attacks.
- Researchers demonstrated a Zero-Day Flagship Phone Ambush using a Samsung Galaxy Z Fold7 to show how new devices can be blocked before public release.
- The 3GPP and GSMA currently lack standardized protocols for verifying the identity or ownership of individuals reporting lost or stolen devices.
Why It Matters
These vulnerabilities transform a theft-prevention tool into a remote denial-of-service vector for any device relying on cellular connectivity. For the streaming and smart home ecosystem, this exposes a critical weakness in hardware that uses cellular IoT as a failover for Wi-Fi, potentially rendering security cameras and gateways useless without physical tampering. The lack of standardized identity verification between carriers means a single fraudulent report can propagate globally, creating a scalable risk for high-value hardware launches. Watch for the GSMA device security group to issue new IMEI protection requirements and multi-factor verification standards for carrier reporting portals.
Additional Context
The GSMA has long maintained the IMEI database as a global mechanism for tracking stolen and lost devices, but the system's trust model has come under increasing scrutiny. In early 2025, the GSMA published updated guidelines for its Device Check service, which allows carriers and law enforcement to query IMEI status across participating networks, expanding the program to include more than 150 operators in 45 countries. That expansion, however, also widened the attack surface that Michigan State University researchers exploited, since each additional participating carrier introduces another potential entry point for fraudulent blacklist submissions. The GSMA's own security working group has acknowledged that IMEI-based reporting relies heavily on carrier-side verification, a gap the MSU team's findings directly expose.
3GPP, the standards body responsible for 4G and 5G specifications, has addressed device identity in its Release 18 and Release 19 work streams, but IMEI blacklisting procedures remain largely outside its formal specification scope. 3GPP's Security Aspects working group (SA3) completed a study item on 5G system security enhancements in late 2024, which examined subscription identifier protection and authentication improvements but did not mandate changes to how operators handle lost-device reports at the signaling layer. This regulatory gap means that individual carriers implement their own verification workflows for IMEI blacklisting, creating inconsistent protections that vary by region and operator. The Federal Communications Commission has not issued specific guidance on IMEI fraud, though the FCC's 2024 enforcement actions against SIM-swapping schemes signaled growing regulatory attention to device identity security.
Samsung, whose Galaxy Z Fold7 was specifically named in the MSU research as a device susceptible to remote blacklisting, has invested in hardware-level security through its Knox platform. Samsung announced at Mobile World Congress 2025 that Knox Matrix would extend cross-device trust verification to include IMEI integrity checks on foldable devices, a move that could partially mitigate the attack vector if carriers adopt the corresponding verification protocols. Meanwhile, independent security researchers have demonstrated related IMEI manipulation techniques in controlled settings. A team from ETH Zurich presented findings at the 2025 IEEE Symposium on Security and Privacy showing that baseband-level IMEI spoofing remains feasible on commercial 5G modems, reinforcing the MSU team's conclusion that the current reporting infrastructure lacks cryptographic binding between a device's reported identity and its actual hardware.
Read full article at msutoday.msu.edu
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source