What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SMS-based provisioning can become a phishing risk when a phone accepts a configuration message and a user approves settings supplied by an attacker. In a September 4, 2019 report, Check Point Research described this issue in certain implementations from Samsung, Huawei, LG, and Sony, including a scenario that could route internet traffic through an attacker-controlled proxy. The report documented specific devices and software at that time; it does not show that current Android phones generally remain vulnerable.

What an SMS provisioning message does

Mobile operators can use over-the-air provisioning to deliver network settings to a phone, such as the address used for MMS. Open Mobile Alliance Client Provisioning (OMA CP) is one standard for carrying these configuration instructions. A phone that processes such a message may display a prompt asking the user to accept the proposed settings.

That normal configuration process can be abused if a device accepts a weakly authenticated or unauthenticated message and the user is persuaded to approve it. The risk is not that every ordinary text message can silently change a phone: in the attack flows Check Point described, user acceptance was a necessary step.

How the phishing attack worked in the 2019 report

The attacker proposes a setting

Check Point Research said some tested implementations accepted OMA CP messages with limited authentication. It also reported that Samsung devices in its research accepted unauthenticated OMA CP messages. A malicious configuration could, for example, set an attacker-controlled proxy, potentially routing internet traffic through infrastructure chosen by the attacker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Samsung Galaxy A17 5G Smart Phone 128GB US 1 Yr Manufacturer Warranty Black
  • YOUR CONTENT, SUPER SMOOTH: The ultra-clear 6.7" FHD+ Super AMOLED display of Galaxy A17 5G helps bring your content to life, whether you're scrolling through recipes or video chatting with loved ones.¹
  • LIVE FAST. CHARGE FASTER: Focus more on the moment and less on your battery percentage with Galaxy A17 5G. Super Fast Charging powers up your battery so you can get back to life sooner.²
  • MEMORIES MADE PICTURE PERFECT: Capture every angle in stunning clarity, from wide family photos to close-ups of friends, with the triple-lens camera on Galaxy A17 5G.
  • NEED MORE STORAGE? WE HAVE YOU COVERED: With an improved 2TB of expandable storage, Galaxy A17 5G makes it easy to keep cherished photos, videos and important files readily accessible whenever you need them.³
  • BUILT TO LAST: With an improved IP54 rating, Galaxy A17 5G is even more durable than before.⁴ It’s built to resist splashes and dust and comes with a stronger yet slimmer Gorilla Glass Victus front and Glass Fiber Reinforced Polymer back.

The message is paired with social engineering

The configuration prompt creates the phishing opportunity: the attacker tries to make the request look legitimate enough for the recipient to accept. In one flow described by Check Point, an attacker first sent a deceptive text claiming to be from the operator and naming a PIN, then sent a provisioning message authenticated with that PIN. Some other flows required the attacker to know the target’s IMSI, a subscriber identifier. These are details of the report’s 2019 findings, not evidence that the same paths work on current phones.

Check Point’s report authors, Artyom Skrobov and Slava Makkaveev, wrote on September 4, 2019: “We emphasize that there is no authenticity check for the attacker to overcome: all that is needed is for the user to accept the CP.” That sentence describes the tested attack flow in their report; it should not be taken as a statement about all devices or today’s provisioning systems.

Rank #2
Tracfone Motorola Moto G 2025, 64GB, Saphire Blue (Locked to
  • Carrier: This phone is locked to Tracfone, which means this device can only be used on the Tracfone wireless network. Tracfone plan required, activating is easy, just 3 steps.
  • DISPLAY: Immersive viewing on a 6.7-inch super-bright 120Hz display with powerful stereo speakers and Bass Boost for cinematic entertainment.
  • CAMERA SYSTEM: Advanced 50MP Quad Pixel camera captures sharp, detailed photos and videos in any lighting condition
  • PERFORMANCE: Lightning-fast 5G connectivity paired with a powerful processor and RAM Boost for smooth multitasking.
  • BATTERY LIFE: Long-lasting 5000mAh battery with TurboPower charging technology delivers hours of power in minutes.

Which devices and fixes the report covered

Check Point published the disclosure on September 4, 2019, after notifying vendors in March. It said it verified its proof of concept on a Huawei P10, LG G6, Sony Xperia XZ Premium, and a range of Samsung Galaxy phones that included the S9. Those are historical test devices, not a list of currently vulnerable models.

Vendor What Check Point reported in 2019
Samsung Check Point said a fix for the described phishing flow was included in the May Security Maintenance Release, identifier SVE-2019-14073.
LG Check Point said LG released a fix in July, identifier LVE-SMP-190006.
Huawei Check Point said Huawei planned user-interface fixes for a subsequent Mate or P series generation.
Sony Check Point said Sony declined to acknowledge the vulnerability and stated that its devices followed the OMA CP specification.

These statements reflect the vendors’ responses as reported by Check Point in 2019. They are not an exhaustive patch inventory, do not establish the status of every model from these manufacturers, and do not verify the current status of any specific phone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Samsung Galaxy A17 5G Smart Phone 128GB, US 1 Yr Manufacturer Warranty Blue
  • YOUR CONTENT, SUPER SMOOTH: The ultra-clear 6.7" FHD+ Super AMOLED display of Galaxy A17 5G helps bring your content to life, whether you're scrolling through recipes or video chatting with loved ones.¹
  • LIVE FAST. CHARGE FASTER: Focus more on the moment and less on your battery percentage with Galaxy A17 5G. Super Fast Charging powers up your battery so you can get back to life sooner.²
  • MEMORIES MADE PICTURE PERFECT: Capture every angle in stunning clarity, from wide family photos to close-ups of friends, with the triple-lens camera on Galaxy A17 5G.
  • NEED MORE STORAGE? WE HAVE YOU COVERED: With an improved 2TB of expandable storage, Galaxy A17 5G makes it easy to keep cherished photos, videos and important files readily accessible whenever you need them.³
  • BUILT TO LAST: With an improved IP54 rating, Galaxy A17 5G is even more durable than before.⁴ It’s built to resist splashes and dust and comes with a stronger yet slimmer Gorilla Glass Victus front and Glass Fiber Reinforced Polymer back.

How this differs from Android’s authorized carrier configuration

Android documents a separate carrier-configuration path for Android 6.0 and later. Under that mechanism, carrier-specific settings are provided by privileged apps whose signing certificate matches a certificate on the SIM. The documented settings include roaming behavior, voicemail, SMS/MMS network settings, and VoLTE/IMS configurations. See the Android Open Source Project documentation on carrier configuration.

Mechanism How settings are delivered or installed What authorizes the source
OMA CP, as discussed in Check Point’s 2019 report A provisioning message can propose settings; the report’s attack flows relied on the recipient accepting the prompt. The report discusses OMA CP message authentication and found weak or absent authentication in certain implementations. The report does not establish current behavior across Android phones.
Android carrier configuration, as documented by AOSP A privileged carrier app supplies carrier-specific configuration. The app’s certificate must match one on the SIM, as described in the AOSP documentation.

These mechanisms should not be treated as interchangeable. The AOSP documentation describes an authorized configuration path; by itself, it does not prove that every manufacturer removed or changed all OMA CP handling.

Rank #4
Sale
Samsung Galaxy S26 Ultra, Unlocked Android Smartphone, 512GB, Black
  • PRIVACY DISPLAY: Automatically hide your screen from those beside you. The built-in privacy display can be preset¹ to turn on when receiving notifications, typing passwords, or using specific apps
  • TYPE IT IN. TRANSFORM IT FAST: Enhance any shot in seconds on your smartphone by using Photo Assist² with Galaxy AI.³ Add objects, restore details, or apply new styles by simply typing or tapping
  • NIGHTS, CAPTURED CLEARLY: From gigs to city lights, record and capture moments after dark with clarity using Nightography so your photos and videos stay crisp and clear on your Samsung Galaxy
  • MAKE IT. EDIT IT. SHARE IT: Turn everyday moments into something personal with creative tools built right into your mobile phone, whether it’s a special contact photo, custom wallpaper, an invitation or more⁴
  • HELP THAT KEEPS UP: Stay in the moment while Now Nudge with Galaxy AI helps you respond faster and stay organized with smart suggestions⁵ that appear exactly when you need them on your phone
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Do not confuse OMA CP with SMS blaster phishing

SMS blaster fraud is a related but different threat. In an August 1, 2024 post, Google’s Android Security & Privacy Team described false base stations, also called cell-site simulators, that inject phishing SMS while bypassing the carrier network and its anti-spam and anti-fraud filters. Google wrote: “This method to inject messages entirely bypasses the carrier network, thus bypassing all the sophisticated network-based anti-spam and anti-fraud filters.” Google said devices remain vulnerable to this type of fraud while they support 2G. Read Google’s explanation of cellular fraud and SMS blasters.

In short, the 2019 OMA CP disclosure concerned a provisioning payload and whether particular device implementations accepted proposed settings. The SMS blaster discussion concerns deceptive SMS injected using a rogue cellular base station. One should not be used as evidence that the other is present on a particular phone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Best Value
Tracfone Moto g Play 2024 Prepaid Phone with a 1-Yr Plan Included
  • Carrier: This phone is locked to Tracfone, which means this device can only be used on the Tracfone wireless network. Activating is easy, just 3 steps.
  • ACTIVATION Promotion: Includes 1500 min, 1500 texts & 1500 MB Data + add more as you need it
  • CAMERA SYSTEM: 50MP Quad Pixel camera. Capture sharper, more vibrant photos day or night with 4x the light sensitivity.
  • PERFORMANCE: Blazing-fast Qualcomm performance. Get the speed you need for great entertainment with a Snapdragon 680 processor and 4GB of RAM.
  • 64GB built-in storage. Get plenty of room for photos, movies, songs, and apps. Made for US

What Android users can take away

  • Treat an unexpected prompt to install carrier or network settings cautiously, especially if an unsolicited text has just told you to expect it. Do not approve a configuration request solely because a message claims to come from your operator.
  • If you receive a suspicious prompt, decline it and contact your mobile operator through a number or support channel you already trust to ask whether a configuration change is legitimate.
  • Do not infer that all Android phones, all SMS messages, or all provisioning systems are vulnerable from Check Point’s device-specific 2019 report.
  • The report stated that Samsung and LG fixes were released in 2019 and that Huawei planned user-interface changes, but it does not establish the current patch status of individual models. Check your phone maker or carrier for model-specific support and security-update information.
  • Google’s warning about SMS blasters concerns a separate risk associated with 2G support; it does not establish an OMA CP vulnerability on your device.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.