A security investigation has raised concerns over a vulnerability in mobile networks that can allow callers to obtain sensitive technical information about a smartphone before the recipient answers the call.
According to a report by Cybernews, an investigation by German public broadcaster Bayerischer Rundfunk (BR) found that incoming calls could expose a phone’s 15-digit IMEI number, device model and operating system version under certain network configurations.
The researchers confirmed the issue through more than 70 test calls across Germany’s major mobile networks. The IMEI was found to be exposed in some cross-network calls involving Telekom and Telefónica’s O2 network, while device model and operating system information was also observed in certain cases.
The vulnerability is linked to the way some Voice over LTE (VoLTE) networks handle call-setup information. The technical data can reportedly be transmitted during the process of connecting a call, meaning the recipient does not necessarily need to answer for the information to be exposed.
Following the findings, the Global System for Mobile Communications Association (GSMA) warned more than 1,000 mobile network operators to review their systems and remove unnecessary device information from call signaling.
The GSMA said the issue appears to involve certain VoLTE configurations that can inadvertently reveal device identifiers. It has also provided network operators and technology vendors with guidance on addressing the problem.
The exposure of an IMEI alone does not automatically give an attacker control over a smartphone. However, researchers and security officials have warned that information such as a device’s model and operating system version could help attackers identify potential targets and vulnerabilities.
Germany’s Federal Office for the Protection of the Constitution reportedly classified the issue as security-relevant, particularly because leaked device information could potentially assist targeted attacks.
The investigation also found that German mobile operators have taken steps to address the problem. However, the global alert from the GSMA means other operators have been urged to check whether similar configurations exist on their networks.
For ordinary users, the report highlights a broader privacy concern: mobile network infrastructure itself can potentially expose technical information from smartphones without any action by the user.
