Researchers and CERT/CC disclosed a serious flaw in Verizon's VoLTE implementation, alleging the carrier's IMS core voice network lacked required IPsec ESP protection for SIP signaling between user equipment and the P-CSCF after IMS AKA authentication. According to the disclosure tied to CERT/CC advisory VU#615987, observed registration traffic was missing expected security headers and analysts reportedly found no encrypted signaling during active voice calls across multiple devices and operating systems, despite 3GPP TS 33.203 and GSMA IR.92 requirements.
The reported exposure could allow an on-path attacker to intercept and manipulate cellular signaling, enabling call hijacking, spoofing, denial-of-service, and potentially misrouting emergency calls. Apple released iOS 26.5 with updated carrier settings, but the disclosure said that did not confirm effective protections were active in production, and researchers further claimed Verizon stopped cooperating with coordinated vulnerability disclosure efforts and had not provided verifiable evidence that the issue was mitigated.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed a severe flaw in Verizon's IMS core voice network, alleging required cryptographic protections for SIP signaling were absent. The disclosure says exposed signaling could enable interception and manipulation of traffic, including call hijacking, spoofing, denial-of-service, and emergency-call misrouting.
Apple released iOS 26.5 with updated carrier settings. The reporting notes this occurred amid the Verizon IMS vulnerability story, but says it does not verify that effective protections are active in production.
CERT/CC published VU#615987 describing missing IPsec integrity protection for IMS SIP signaling in Verizon VoLTE deployments. The advisory documents the issue as a product vulnerability affecting Verizon's VoLTE environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.