By Ayomide Otitoju
The National Information Technology Development Agency (NITDA) has issued a public alert on a newly discovered critical security vulnerability in embedded SIM (eSIM) cards, warning that the flaw could expose billions of devices worldwide to cyberattacks.
In a statement on Friday, the agency said the vulnerability affects more than 2 billion smartphones, tablets, wearables, and Internet of Things (IoT) devices, with attackers now exploiting it to hijack phone numbers, intercept communications, and install malicious applets.
According to NITDA, the flaw originates from the GSMA TS 48 Generic Test Profile (versions 6.0 and earlier), widely used in radio compliance testing of embedded Universal Integrated Circuit Card (eUICC) chips. If exploited, attackers could gain physical or remote access to targeted devices, enabling them to extract sensitive cryptographic keys, clone eSIM profiles, and deploy stealth backdoors at the SIM card level.
“This could result in widespread interception of communications and persistent device compromise,” the agency cautioned.
To mitigate the risks, NITDA advised device manufacturers and service providers to immediately apply Kigen OS patches via over-the-air (OTA) updates, adopt the latest GSMA TS 48 version 7.0 standard, and phase out legacy test profiles vulnerable to malicious exploitation. It stressed that urgent action is essential to block exploitation paths and safeguard users from one of the most far-reaching cybersecurity threats in recent years.
The eSIM, a digital SIM embedded in devices to replace physical SIM cards, was introduced in Nigeria in 2020 when the Nigerian Communications Commission (NCC) approved MTN and 9mobile to conduct a one-year trial involving 5,000 eSIMs. Both operators later rolled out commercial eSIM services, with Airtel joining in January 2023.
While the technology is gaining ground, there is currently no publicly available data on the number of Nigerians using eSIMs.
