Skip to finding
§
High
Mobile
Confirmed

A low-cost rogue 5G cell can silently track subscribers, force downgrades and freeze modems on commercial networks.

Idle and inactive phones can camp on the transmitter automatically, before authentication and without warning.

Affects

Commercial 5G SA and NSA networks and ordinary consumer phones or cellular modems operating within a rogue base station's coverage.

What it enables

User-invisible subscriber tracking, radio-generation downgrade and persistent modem denial of service

Observe the target operator's MCC, MNC, frequency plan and reselection priorities→↓Broadcast a stronger or higher-priority cell using open-source stacks and inexpensive SDR hardware→↓The idle device autonomously camps on the rogue cell without a warning or user interaction→↓Request permanent, concealed or temporary subscriber identifiers and correlate successive GUTIs→↓Send unauthenticated Registration Reject causes to force LTE/UMTS downgrade, an infinite retry loop or a frozen modem state requiring a manual radio reset
Why this matters

A low-cost rogue 5G cell can silently track subscribers, force radio-generation downgrades and persistently disrupt modems on commercial networks. Researchers demonstrated the attack against commercial networks and off-the-shelf devices using open-source cellular stacks and inexpensive SDR hardware.

Detail and 2 sources
Required access

Cellular radio range with SDR transmission capability while the target device is in RRC_IDLE or RRC_INACTIVE

Affected versions

Galaxy Z Flip3 / Snapdragon X60, Oppo Find X5 Lite / Dimensity 900, iPhone 13 Pro / Snapdragon X60 as identified by the paper, Google Pixel 8 / Exynos 5300i, Samsung Galaxy S23 / Snapdragon X70, Quectel RM520N-GL / Snapdragon X62, Three anonymized Tier-1 operators across commercial 5G SA and NSA deployments, 3GPP Release 15 and 16 behavior tested across Galaxy Z Flip3, Oppo Find X5 Lite, iPhone 13 Pro, Pixel 8, Galaxy S23, and Quectel RM520N-GL, Galaxy S23 with Snapdragon X70 tested for unauthenticated reject handling on two commercial 5G SA operators

Proof of concept

Demonstrated by the researcher

The attacker observes the operator identifiers, spectrum and reselection priorities, then broadcasts a stronger or higher-priority cell with an open-source stack and inexpensive SDR hardware. A phone in RRC_IDLE or RRC_INACTIVE camps on it without warning or interaction.

The rogue cell can request permanent, concealed or temporary subscriber identifiers and correlate successive GUTIs. Unauthenticated Registration Reject causes can then force an LTE or UMTS downgrade, trap the modem in a retry loop or leave it frozen until the user manually resets its radio state.

Evidence
Paper demonstrates the technique against commercial networks and COTS devicesRecent first publication on 2026-09-21User interaction and warning absence are explicitly measuredTracking and reject-induced modem effects are experimentally characterized
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026