← Back to browse · API

CVE-2019-16256

Severity
CRITICAL
CVSS
9.8
EPSS
0.04949
Risk score
65.93
CISA KEV
Yes
PoC
No
Published
2019-09-12
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-7062, GHSA-MQ4H-3X66-JFC7
Products
SIMalliance:Toolbox Browser, n/a:n/a n/a
Sources
cisa.gov CVE-2019-16256
euvd EUVD-2019-7062

Description

Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.

References