A significant privacy breach in O2 UK’s Voice over LTE (VoLTE) service has enabled anyone to pinpoint the location of O2 customers without their awareness or consent.
This flaw compromised sensitive location data and device identifiers during standard call processes, posing a risk to millions of users since the service’s debut in March 2017.
The vulnerability was only addressed on May 19, 2025, after months of failed attempts to inform O2 privately. It was patched only after the issue became publicly known.
Exposure of Critical Data in O2’s Network
Security expert Daniel Williams uncovered the flaw while testing VoLTE call quality using Network Signal Guru (NSG) on a rooted Google Pixel 8.
His research revealed that O2’s Session Initiation Protocol (SIP) responses contained an unusually high volume of data when compared to other telecom networks.
The issue stemmed from O2’s implementation of the IP Multimedia Subsystem (IMS), particularly in the SIP message headers exchanged during call initiation. Five specific headers stood out as the main points of concern.

The exposed headers disclosed sensitive information such as the International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI) for both the caller and recipient, as well as the recipient’s real-time cell location data.
Accurate Location Tracking
The most concerning detail was found in the Cellular-Network-Info header, which included the Location Area Code (LAC) and the Cell ID associated with the recipient’s active tower, enabling precise tracking of their whereabouts.

Williams showed that by using open-source cell tower databases such as cellmapper.net, the exposed data could be used to track a user’s location with impressive precision. “In urban environments, this data can pinpoint someone’s location very accurately,” Williams noted.
“In crowded cityscapes, numerous small coverage towers are used, often covering as little as 100 square meters per site,” he added.
The researcher even managed to track an O2 customer while they were abroad, successfully identifying their position in the heart of Copenhagen, Denmark.

The issue impacted all O2 users utilizing the “4G Calling” feature, which launched in 2017.
Disturbingly, disabling the 4G Calling feature did not prevent exposure, as the sensitive headers were still visible even when a device could not be reached. This revealed details about the last connected cell and the time elapsed since the connection was made.
The flaw was traced back to O2’s Mavenir Unified Access Gateway (UAG), where incorrect settings led to the inclusion of debugging data in normal call signaling.
This vulnerability had the potential to affect O2’s 23 million mobile customers, leaving them open to location tracking by anyone with a phone number and basic technical expertise.
Williams expressed frustration with O2’s lack of a straightforward vulnerability reporting process, noting the contrast with EE’s transparent and structured disclosure approach.
This breach underscores the persistent privacy risks in telecommunications systems and emphasizes the critical need for proper security configurations in complex services like VoLTE.




