5G Security Risks: How Fake Base Station Tracking Threatens Subscriber Privacy
A low-cost counterfeit base station remains capable of monitoring 5G networks
Researchers associated with the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe developed an economical device known as 5G-Shark designed to intercept mobile devices by redirecting them to a simulated network node. The system was utilized to evaluate commercial 5G infrastructure, revealing vulnerabilities in identity protection mechanisms. During tests on standalone 5G networks, service providers successfully obscured user identifiers in all instances except one. However, the same networks generated temporary identification numbers with predictable sequences that enabled continuous surveillance. The 5G standard was intended to eliminate IMSI tracking, a method that coerces devices into disclosing their unique identification codes. The 5G-Shark tool exploits a vulnerability in the cell reselection process, where devices autonomously select network cells based on broadcast signals. These signals lack authentication protocols, allowing a malicious node to mimic high-priority connections with strong signal strength. The device operates using open-source networking software and affordable software-defined radio equipment, remaining undetectable to users who experience no alerts or disruptions.
Once a mobile device connects to the spoofed cell, it transmits a temporary identifier called the GUTI, which is periodically rotated to prevent exposure of the permanent identity. The research team analyzed 3,742 such identifiers across three network operators. For one provider operating both network types and another using legacy infrastructure, consecutive temporary IDs advanced in nearly sequential increments, covering only 0.11% of the available range compared to the expected 29% from random allocation. This pattern enabled tracking rates between 84% and 96%. One operator implemented a more secure approach, rotating identifiers by approximately 29% of the range each time, resulting in only 7% of consecutive registrations remaining traceable. This discrepancy highlights how identical standards can produce varying levels of security based on implementation choices.
The study categorizes vulnerabilities into two classifications: mandatory compliance requirements, such as identity verification and unauthenticated rejection message processing, and configurable factors like predictable temporary ID generation. Malicious actors demonstrated the potential for disruptive outcomes by transmitting specially crafted Registration Reject messages. This action forced a Samsung Galaxy S23 into a restricted 3G mode without data access, while other error codes triggered infinite retry loops or frozen modems requiring manual intervention. These issues occurred consistently across both standalone network operators, suggesting a firmware-level flaw rather than operator-specific policies.
The research remains a preprint submitted to IEEE and has not undergone formal peer review. Testing involved the researchers’ personal devices on live commercial networks, with operators identified only as A, B, and C. The attack requires proximity to the target device and relies on the phone being in an idle state, affecting a limited set of seven devices. The findings underscore persistent risks in 5G security architecture, emphasizing the need for stricter implementation of
