LIVE · cybersecurity feed
Live wire
CVE-2026-8233high

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Researchers have identified a significant class of 84 previously unknown vulnerabilities, dubbed 'iTrue' flaws, affecting the core networks of 4G and 5G mobile systems. These vulnerabilities stem from implicit trust errors between network functions, exacerbated by the shift to cloud-native deployments. Exploitation could lead to denial-of-service attacks and session hijacking, where an attacker seizes control of a user's network session.

zeroday.news · 2d ago

Researchers have reported the discovery of 84 previously unknown vulnerabilities affecting the core networks of 4G and 5G mobile systems. These flaws, collectively termed 'iTrue' vulnerabilities, are described as stemming from implicit trust errors between various network functions within the core infrastructure. The report indicates that these issues could potentially be exploited to facilitate denial-of-service attacks and session hijacking.

The technical mechanism behind these 'iTrue' flaws is rooted in scenarios where network functions implicitly trust each other without sufficient validation or authentication. This implicit trust, when exploited, allows an attacker to bypass security controls by masquerading as a legitimate network component or by manipulating trusted communication paths. The shift towards cloud-native deployments in 4G and 5G core networks is cited as a factor that exacerbates these vulnerabilities, likely due to the increased complexity and dynamic nature of inter-service communication in such environments.

One of the most significant potential impacts highlighted is session hijacking. In a session hijacking scenario, an attacker could seize control of a legitimate user's network session. This could grant the attacker unauthorized access to services or data associated with that session, potentially leading to privacy breaches, unauthorized transactions, or further network compromise. Denial-of-service attacks are also a reported risk, where an attacker could disrupt network availability or specific services by overwhelming or disabling critical core network functions.

While specific vendors or products were not named, these vulnerabilities affect the core networks of both 4G and 5G mobile systems. This implies that the issues are likely present in the implementations of various network equipment providers and telecommunication operators globally, given the widespread adoption of these standards. The scope could therefore be broad, impacting a significant portion of the global mobile subscriber base if exploited.

Mitigation for this class of implicit trust errors typically involves implementing robust authentication and authorization mechanisms between all network functions, even those considered internal or trusted. This includes mutual authentication, stricter input validation, and comprehensive integrity checks for all inter-component communications. Network segmentation and micro-segmentation can also limit the blast radius of an exploit, preventing an attacker from easily moving laterally across the core network. Regular security audits and penetration testing focused on inter-service communication flows are also crucial for identifying and remediating such vulnerabilities.

The discovery of these 'iTrue' vulnerabilities underscores the ongoing security challenges inherent in complex, interconnected network infrastructures, particularly as they evolve towards cloud-native architectures. As mobile networks become increasingly critical for a wide array of services, from personal communication to industrial IoT, the security of their core components remains paramount. This report highlights the continuous need for rigorous security research and proactive measures to secure the foundational elements of global telecommunications.

mobile security5g4gvulnerabilitiessession hijacking
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems

OpenAI has revealed Astra, an unreleased model designed to tackle complex, long-running tasks, after an internal version produced ten significant advances in mathematics and theoretical computer science. [...]

vulnerability

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

breach

CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. […]

ai

SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform

CALIFORNIA, USA, 2nd August 2026, CyberNewswire

cloud

Welcome to Agents Week

Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.

security

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]