Security Explorations reveals critical flaws in Kigen's GSMA-certified eSIMs, enabling profile theft, app injection, and user impersonation. The exploit leverages 2019 Java Card bugs, undermining trust in eUICC isolation and GSMA certification. Mitigation and disclosure coordination followed.