Overview
- A Bayerischer Rundfunk investigation published Thursday found that in more than 70 test calls German networks sometimes sent full device identifiers (IMEIs) and device or OS details to callers during call setup before the call was answered.
- Telekom and Telefónica (O2) were shown to have leaked IMEIs in several tests while Telekom and Vodafone also exposed phone models and operating‑system versions in some call configurations, using VoLTE/IMS signaling paths that forwarded unnecessary device metadata.
- The GSMA confirmed the issue to BR, circulated a nine‑page briefing to its members recommending network checks and filtering, and the three major German operators said they have implemented or announced technical mitigations to limit the data sent during call setup.
- The Bundesamt für Verfassungsschutz called the flaw 'sicherheitsrelevant' and warned that foreign intelligence services and criminals could use IMEIs to build movement profiles, identify targets, enable tailored spyware or attempt IMEI‑cloning attacks.
- Key questions remain unanswered: regulators and standards bodies say the specifications do not require IMEI forwarding, investigations and network audits are ongoing, and it is still unclear how long the vulnerability existed or whether it was ever exploited before disclosure.