A phone call you never answer may still reveal information about your device. A recent investigation into German mobile networks found that certain VoLTE configurations exposed technical data during call setup—including the phone’s IMEI number, model and operating system version.
The information could reach the caller as soon as the target phone started ringing. Answering the call was not required.
Why is the leak dangerous?
An IMEI is a unique 15-digit identifier assigned to a mobile device. On its own, it does not give someone access to your phone or reveal its live location. However, combined with the device model and software version, it can help an attacker:
- identify a specific phone,
- check whether it may have known security vulnerabilities,
- prepare convincing device-specific phishing messages,
- associate a device with its owner and monitor its activity across networks.
The vulnerability was documented by Bayerischer Rundfunk, which conducted more than 70 test calls. Following the disclosure, the GSMA informed over 1,000 mobile operators worldwide and advised them to review their network configurations.
How can you protect your phone?
Because this is primarily a network configuration issue, the permanent fix must be implemented by mobile operators. Users should contact their carrier and ask whether the relevant VoLTE privacy patches have been applied.
For sensitive conversations, consider using end-to-end encrypted calling apps such as Signal or WhatsApp. You should also keep your phone updated, as exposed software-version information is more useful to attackers when a device is missing security patches.
On an iPhone, go to Settings → General → Software Update → Automatic Updates and enable all available update options. Android users should check the System Update or Software Update section in Settings.
The leak does not mean that every unanswered call exposes your IMEI. It does show, however, that mobile network security depends not only on the phone in your hand, but also on how your carrier configures its infrastructure.
Recent Comments