CVE-2019-16256: SIMalliance Toolbox Browser Command Injection Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 4.9% chance of exploitation in the next 30 days.

Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

Affected products

Published 2019-09-12. Last modified 2026-06-17.