An investigation by German public broadcaster Bayerischer Rundfunk (BR) has found that mobile networks in Germany exposed sensitive data from a recipient's phone to the person calling it, according to tagesschau. Germany's domestic security agency, the Verfassungsschutz, assesses that foreign intelligence services have already exploited the flaw, the broadcaster reported.

BR's reporting does not name which carriers are affected, specify what categories of device data leaked, or say whether the vulnerability has since been fixed — details that would show how many subscribers were exposed and for how long.

The Verfassungsschutz's assessment moves the flaw from a technical curiosity to a state-level security concern. If hostile intelligence services can extract device information by placing a call, they gain a low-cost way to locate or fingerprint a target's phone without the target knowing.

Hypothesis: because mobile networks interconnect across borders to route international calls, a structural weakness of this kind is unlikely to stop at Germany's frontier. Supporting this: BR frames the issue as a weakness in how networks handle calls generally, not a single carrier's misconfiguration, per tagesschau. Against this: the investigation examined only German networks, and the report does not claim the flaw exists elsewhere or has been tested abroad.

This article summarizes findings reported by German media. It is not legal or security advice.

It remains unclear whether Germany's telecoms regulator or counterparts elsewhere in the EU will examine their own networks for the same weakness; tagesschau has not reported a formal response from network operators.