search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments

Vulnerability Note VU#615987

Original Release Date: 2026-06-02 | Last Revised: 2026-06-02

Overview

VoLTE deployments on Verizon’s IMS network have operated without negotiated SIP integrity protection. In observed test conditions, SIP signaling—including registration, call setup, and messaging—traveled without IPsec ESP encapsulation and without SIP Security Agreement headers, exposing it to interception and modification by on-path attackers.

Recent carrier configuration updates, including Apple’s iOS 26.5 carrier bundle released on May 11, 2026, include IMS IPsec–related settings. However, such configuration entries do not confirm active deployment, successful negotiation, or functional protection in production.

Description

CVE-2026-10629
Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no ESP-encapsulated SIP traffic was detected during subsequent signaling such as INVITE, MESSAGE, BYE, and UPDATE. This pattern persisted across devices, operating systems, and network conditions, indicating a deliberate network configuration rather than a transient issue.

Per 3GPP TS 33.203 and GSMA IR.92, SIP signaling between the UE and P-CSCF must be protected using IPsec ESP following IMS AKA authentication, with negotiation occurring during registration. The absence of this protection allows attackers to manipulate SIP signaling undetected, enabling call hijacking, spoofing, denial-of-service, and misrouting of emergency calls.

Verizon initially acknowledged the issue and stated that integrity support would be available upon request and extended broadly later in the year. However, the company has since ceased participation in coordination, including follow-up discussions and draft review, and has not provided verifiable evidence of mitigation. As remediation remains unconfirmed, this disclosure proceeds to inform users of an ongoing security exposure.

Independent verification would require observation of successful SIP security negotiation, ESP-protected traffic, or official confirmation from Verizon.

Impact

Without integrity protection, on-path attackers can intercept, replay, or alter SIP messages with no risk of detection. This undermines core VoLTE security assumptions and enables signaling spoofing, call disruption, and manipulation of emergency routing.

Although recent configuration changes suggest potential progress, their operational status remains unverified. Until protections are confirmed, the risk persists.

Solution

Remediation requires coordinated network and device-side changes. Verizon must enable and enforce SIP security negotiation and ESP protection in its IMS core infrastructure, and devices must receive and apply correct carrier configuration to support IPsec.

Verification should confirm successful SIP security negotiation and ESP-protected signaling, either through observed headers, traffic capture, or operator confirmation.

Until then, organizations relying on high-assurance VoLTE should treat signaling as untrusted

Acknowledgements

The authors thank DongWon Lee, Jeongmin Choi, and CheolJun Park from Kyung Hee University for their technical analysis, coordination efforts, and identification of the iOS 26.5 configuration updates. Their work has advanced understanding of this issue and ensured disclosures remain grounded in observable evidence.
This report was prepared by Timur Snoke, with AI-assisted drafting to support clarity and accuracy.

Vendor Information

615987
 

Verizon Not Affected

Notified:  2026-04-30 Updated: 2026-06-02

Statement Date:   May 11, 2026

CVE-2026-10629 Not Affected

Vendor Statement

After reviewing the issue you raised, it appears the GSMA and 3GPP provisions you referenced are not mandatory, allowing carriers the flexibility to adopt the protocols at their discretion. Verizon takes the integrity of its network very seriously and appreciates your outreach and concern with regard to this issue.

CERT Addendum

CERT/CC notes that the reporter disputed Verizon’s characterization of the referenced GSMA and 3GPP provisions as “not mandatory.” The reporter cited 3GPP TS 33.203 Sections 6.1.2–6.1.3 and GSMA IR.92 Clauses 7.3 and 14.3, which describe mandatory IMS/VoLTE signaling protection requirements involving IPsec integrity protection for SIP signaling.

The reporter further asserted that GSMA certification processes for VoLTE interoperability and deployment rely on compliance with these specifications. According to the report, observed network behavior indicating the absence of SIP Security headers and ESP traffic may be inconsistent with those specifications or may indicate the use of alternative compensating controls that were not disclosed during coordination.

Verizon did not provide additional technical details regarding compensating security mechanisms or clarify which specific provisions it considered optional within the context of the reported behavior.


Other Information

CVE IDs: CVE-2026-10629
API URL: VINCE JSON | CSAF
Date Public: 2026-06-02
Date First Published: 2026-06-02
Date Last Updated: 2026-06-02 17:27 UTC
Document Revision: 4

Sponsored by CISA.