even if it is actually in read only memory (it is not in smartphones), that does not matter if a vulnerability grants remote code execution ability. it all happens in RAM. it is wiped with a power cycle but the attacker can just reinfect your phone.
to the SIM card’s storage - from which it was impossible to run additional apps because, again, that functionality just didn’t exist.
SIM cards support apps. have been that way for a very long time.
Finally, most true feature phones didn’t have data connections, making it almost impossible to introduce data into memory.
calls and sms are data, with a right vulnerability they can be used to deliver a payload
they could only display an SMS payload as raw text
same with modern phones, and yet attacks are delivered through them, somehow.
even if it is actually in read only memory (it is not in smartphones), that does not matter if a vulnerability grants remote code execution ability. it all happens in RAM. it is wiped with a power cycle but the attacker can just reinfect your phone.
SIM cards support apps. have been that way for a very long time.
calls and sms are data, with a right vulnerability they can be used to deliver a payload
same with modern phones, and yet attacks are delivered through them, somehow.