Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Researchers have uncovered a staggering 84 vulnerabilities in the core software of both 4G and 5G networks, including a potentially catastrophic session hijacking flaw that could allow hackers to intercept sensitive data. The disturbing findings highlight the urgent need for telecommunications companies to prioritize security patches and updates to protect against these newly disclosed weaknesses.

The researchers, who used artificial intelligence (AI) models to scan through millions of lines of code, discovered the vulnerabilities in the Network Function Virtualization (NFV) software that underpins both 4G and 5G networks. NFV is a critical component of modern telecommunications infrastructure, allowing service providers to virtualize network functions such as firewalls and routers. The AI models identified several types of flaws, including buffer overflows, authentication bypasses, and session hijacking vulnerabilities.

One of the most concerning findings was a session hijacking flaw that could potentially allow hackers to intercept sensitive data exchanged between users and their mobile operators. This type of vulnerability is particularly worrying because it can be exploited remotely, without the need for any user interaction or login credentials. Session hijacking attacks are often used by attackers to steal financial information, eavesdrop on conversations, or inject malware into devices.

The researchers estimate that the vulnerabilities could potentially impact hundreds of millions of mobile users worldwide, although they stress that not all of the flaws have been tested in real-world scenarios. The affected telecommunications companies will need to work quickly to identify which specific networks are vulnerable and apply security patches to mitigate the risks. In some cases, operators may also need to replace entire network components or perform manual updates to ensure that their systems are secure.

The discovery of these vulnerabilities serves as a stark reminder of the importance of prioritizing cybersecurity in modern telecommunications infrastructure. As our reliance on mobile devices continues to grow, so too does the potential for hackers to exploit weaknesses in these networks and compromise sensitive data. Telecommunications companies must take immediate action to address these flaws and ensure that their customers’ information is protected.

In light of this research, users should be aware of the risks associated with session hijacking attacks and take steps to protect themselves. This includes using reputable VPNs when accessing public Wi-Fi networks, keeping mobile devices up-to-date with the latest security patches, and being cautious when clicking on links or downloading attachments from unknown sources. By taking these precautions, individuals can reduce their exposure to potential cyber threats and stay safe in an increasingly connected world.


Source: The Hacker News — 2026-07-31