Exploring the Security Landscape of eSIM Technology
Understanding eSIM Technology
Embedded SIMs, also referred to as eSIMs or Kigen eUICC, are revolutionizing mobile connectivity by enabling users to change network operators without needing to physically swap SIM cards. This innovative technology allows for the storage of multiple profiles digitally, facilitating secure over-the-air provisioning that benefits not only smartphones but also Internet of Things (IoT) devices and connected vehicles.
However, a pressing concern has emerged. Security Explorations, a cybersecurity laboratory affiliated with AG Security Research, recently uncovered a significant vulnerability within this technology. They successfully executed a hacking exploit on the eUICC card, revealing critical security flaws within hardware-protected SIM elements. This discovery has prompted the industry to reassess the safety measures surrounding digital SIM solutions.
The Journey to Discovery
The research team at Security Explorations began their analysis in July 2024, focusing on the intricacies of Kigen’s Java Card implementation and its secure enclave. Throughout their investigation, they compiled an extensive amount of data, generating over 4,200 notes detailing various vulnerabilities related to data management within the Java Card virtual machine.
By March 2025, they achieved a remarkable breakthrough: the extraction of the private Elliptic Curve Cryptography (ECC) key that operates as a certificate-signing master credential. This finding was formally communicated to Kigen on March 17, with acknowledgment from the company following shortly after on March 20. The researchers further created a proof-of-concept that demonstrated an over-the-air attack via the SMS-PP protocol, fundamentally challenging previous assumptions about the security of tamper-resistant eSIM hardware.
Why Kigen eUICC Was Targeted
Kigen’s eSIM technology is extensively deployed worldwide, with estimates suggesting it operates across two billion devices. The Java Card VM, built on Infineon’s ARM SecurCore chip, has obtained EAL4+ certification under GSMA TS.48, and Kigen has claimed that their eSIM operating system offers a level of security comparable to traditional SIM cards.
Despite these assurances, the Security Explorations team demonstrated serious vulnerabilities. The exploit relied on long-standing weaknesses within Java bytecode, resulting in several alarming outcomes:
- Extraction of the private ECC key associated with GSMA identity profiles.
- Retrieval of decrypted subscription profiles from major network operators, bypassing encryption safeguards.
- Injection of malicious Java Card applets into existing profiles.
- Creation of cloned eSIMs capable of intercepting communications on a massive scale.
In an unsettling test, the researchers showed that two cloned smartphones could silently receive identical calls and texts, stealing personal communications without alerting the original user.
Following a Responsible Disclosure Path
The team at Security Explorations adhered to a structured process of disclosure regarding their findings. Key milestones in this timeline include:
- March 17, 2025: Proof of the ECC key was delivered to Kigen.
- March 21, 2025: A technical advisory was shared, and Kigen acknowledged the issue.
- By March 31, 2025: The researchers were rewarded with $30,000 for their work.
- April to June 2025: Ongoing technical guidance and lab data were provided.
- April 7 & 10, 2025: Notifications were sent to GSMA and Oracle Java Card teams.
- July 2, 2025: Full public disclosure of the findings occurred after a 90-day responsible window.
Assessing the Threat Landscape
The implications of the compromised eUICC are profound. Once the ECC key is exposed, malicious actors gain the ability to extract unencrypted eSIM profiles from operator servers, easily altering or cloning them. This presents a grave risk of identity theft, as cloned eSIMs could masquerade as legitimate users, diverting SMS, calls, and two-factor authentication tokens with no detection.
Further vulnerabilities allow injected applet-level backdoors, which can quiet operators and undermine remote update protocols. If predictable profile identifiers are exploited, large-scale impersonation attacks become feasible. Notably, these vulnerabilities trace back to Java Card bytecode issues identified in 2019, which were previously dismissed but have now been weaponized.
Kigen’s Response and Industry Reaction
In light of these findings, Kigen has undertaken comprehensive mitigation efforts. They have:
- Hardened approximately 180 bytecodes with added type-safety checks.
- Tightened TS.48 Test Profile rules in collaboration with GSMA.
- Applied patches to millions of eSIMs and issued communications through GSMA’s CVD program.
The exploit garnered a CVSS score of 6.7 (environmental) and rose to 9.1 (critical) when network access was considered. However, Kigen opted against releasing a public Common Vulnerabilities and Exposures (CVE) reference, an action that has spurred further discussion in the industry.
Despite GSMA’s recent Application Note aimed at addressing provisioning via Remote Application Management (RAM) keys, critics argue these measures do not tackle fundamental issues of validation within Java Card bytecode execution.
Conclusion: The Call for Reform
This incident not only highlights vulnerabilities within Kigen’s products but also reveals profound issues in the entire industry’s approach to eSIM security. The successful hacking of the eUICC card uncovers a stark truth: the security of eSIMs, previously considered robust due to perceived hardware protections, is now questionable.
To enhance security, the industry must adjust its perspective, treating potential breaches as a given and focusing on robust containment strategies. The road ahead requires transparent standards and rigorous audits to ensure that digital identity protections are not merely promises, but realities that safeguard users globally.


