on 18-05-2025 21:42
This, whilst incredibly technical, was very interesting...
"Any O2 customer can be trivially located by an attacker with even a basic understanding of mobile networking."
"...every O2 device that is making a phone call on IMS (4G Calling / WiFi Calling) is receiving information that can be used to trivially geolocate the recipient of the call."
https://mastdatabase.co.uk/blog/2025/05/o2-expose-customer-location-call-4g/
In this instance, PAYG is more secure, as O2 does not provision 4G Calling/WiFi Calling to their customers on Pay As You Go. I do wonder if those dependent on O2's network but that do offer PAYG clients 4G Calling (like giffgaff?) are equally porous in this regard...?
on 19-05-2025 18:11
Very informative @pgn. There is more about this here :-
O2 UK Fixes VoLTE Flaw that Exposed User Mobile Location Data - ISPreview UK
on 19-05-2025 19:05
Saw the article and read with interest. How long has this has been known about and is it another example of O2 taking an inordinate length of time to fix?
I rarely make or receive important calls over O2 as I've never been prepared to risk losing my long term number transferring it.
on 19-05-2025 19:11
on 19-05-2025 19:11
on 19-05-2025 19:48
on 19-05-2025 19:48
on 19-05-2025 20:34
NOTE: O2 first introduced their implementation of IMS / 4G Calling all the way back in 2017.
....so 7-8 years for a fix?
Seems standard for O2!
19-05-2025 20:38 - edited 19-05-2025 20:41
19-05-2025 20:38 - edited 19-05-2025 20:41
Ah yes, @jonsie - I meant the time between the two articles - had the first not been published, alongside author's exhortations to Lutz Schüler CEO of VMO2, the press release to ISPreview would probably still be forthcoming!
"Update (19th May 2025, 08:14 BST)
O2 reached out to me via email to confirm that this issue has been resolved. I have validated this information myself, and can confirm that the vulnerability does appear to be resolved."
Or someone left the debug-flag set on the production code on O2's side, so a quick fix 🙃
on 20-05-2025 20:02
on 20-05-2025 20:02
on 16-06-2025 22:40
Glad I don't have anyone ringing that's important