cancel
Showing results for 
Search instead for 
Did you mean: 

O2 VoLTE: locating any customer with a phone call

pgn
Level 78: King of Kings
  • 41957 Posts
  • 248 Topics
  • 1862 Solutions
Registered:

This, whilst incredibly technical, was very interesting...

"Any O2 customer can be trivially located by an attacker with even a basic understanding of mobile networking."

"...every O2 device that is making a phone call on IMS (4G Calling / WiFi Calling) is receiving information that can be used to trivially geolocate the recipient of the call."

 

https://mastdatabase.co.uk/blog/2025/05/o2-expose-customer-location-call-4g/

 

In this instance, PAYG is more secure, as O2 does not provision 4G Calling/WiFi Calling to their customers on Pay As You Go. I do wonder if those dependent on O2's network but that do offer PAYG clients 4G Calling (like giffgaff?) are equally porous in this regard...?

 

1000050253.gif

 

Message 1 of 9
987 Views
8 REPLIES 8

Oxonian
Level 39: Midshipman
  • 14198 Posts
  • 366 Topics
  • 38 Solutions
Registered:

Enlli
Level 70: Enigma
  • 10017 Posts
  • 93 Topics
  • 1926 Solutions
Registered:

Saw the article and read with interest. How long has this has been known about and is it another example of O2 taking an inordinate length of time to fix?

I rarely make or receive important calls over O2 as I've never been prepared to risk losing my long term number transferring it.

This is not O2 and we are all customers here similar to yourself and cannot answer account type queries.
Message 3 of 9
853 Views

Cleoriff
Level 94: Supreme
  • 131019 Posts
  • 838 Topics
  • 7611 Solutions
Registered:

Interesting and worrying @pgn 😖

Veritas Numquam Perit

Girl in a jacket
Message 4 of 9
851 Views

pgn
Level 78: King of Kings
  • 41957 Posts
  • 248 Topics
  • 1862 Solutions
Registered:

Hmm. News released to ISPreview today, eh? Pretty quick turnaround from the date of the earlier post, @Oxonian @ I wonder what else they broke in their haste to patch the leak...🤔

Message 5 of 9
844 Views

jonsie
Level 94: Supreme
  • 97318 Posts
  • 615 Topics
  • 7215 Solutions
Registered:

NOTE: O2 first introduced their implementation of IMS / 4G Calling all the way back in 2017.

 

....so 7-8 years for a fix?

Seems standard for O2!

Message 6 of 9
817 Views

pgn
Level 78: King of Kings
  • 41957 Posts
  • 248 Topics
  • 1862 Solutions
Registered:

Ah yes, @jonsie - I meant the time between the two articles - had the first not been published, alongside author's exhortations to Lutz Schüler CEO of VMO2, the press release to ISPreview would probably still be forthcoming!

"Update (19th May 2025, 08:14 BST)

O2 reached out to me via email to confirm that this issue has been resolved. I have validated this information myself, and can confirm that the vulnerability does appear to be resolved."

Or someone left the debug-flag set on the production code on O2's side, so a quick fix 🙃

Message 7 of 9
815 Views

Oxonian
Level 39: Midshipman
  • 14198 Posts
  • 366 Topics
  • 38 Solutions
Registered:

@jonsie wrote:

NOTE: O2 first introduced their implementation of IMS / 4G Calling all the way back in 2017.

 

....so 7-8 years for a fix?

Seems standard for O2!


 

There's hope for the Forum popup yet ! 👍

Message 8 of 9
738 Views

Pipstop78
Level 12: Nimble
  • 772 Posts
  • 281 Topics
  • 2 Solutions
Registered:

Glad I don't have anyone ringing that's important 

Message 9 of 9
47 Views