O2 Service Vulnerability Exposed User Location

O2 Service Vulnerability Exposed User Location

A vulnerability in O2’s 4G Calling service exposed user location data through network message headers, allowing potential attackers to pinpoint users’ locations. The issue affected all users from the service’s launch until a recent fix was implemented, highlighting risks in voice over LTE technology. #O2 #4GCalling #LocationLeakage #Cybersecurity

Keypoints

  • The vulnerability involved the exposure of user location and device identifiers in network message headers.
  • Any device supporting IMS-based VoLTE on O2’s network was potentially susceptible to location tracing.
  • Attackers could determine user locations with high precision, even in urban areas.
  • The issue persisted from the launch of O2’s 4G Calling in March until a recent security patch was applied.
  • O2 confirmed that a full fix has been implemented, and customers do not need to take further action.

Read More: https://www.securityweek.com/o2-service-vulnerability-exposed-user-location/