O2 UK Fixed VoLTE Flaw that Exposed User Mobile Location Data UPDATE
June 28, 2025

Vulnerability Details: CVE-2024-53026. It is a vulnerability affecting O2 UK’s VoLTE/IMS service, disclosed in mid-May 2025. Rated Low, with a CVSS v3 score of 3.5. It has a limited impact on confidentiality and no effect on integrity or availability. What Happened? When one user places an IMS call, the network improperly exposes a “Cellular‑Network‑Info” SIP header. This […]