SIM cards do run some sophisticated software, e.g. a. Java Card runtime.
I can't tell if this is true or false, but it seems that in either case, access to the SIM can imply access location data:
> With the all-important (and till-now elusive) encryption key, Nohl could send a virus to the SIM card, which could then send premium text messages, collect location data, make premium calls or re-route calls.
[1] https://www.forbes.com/sites/parmyolson/2013/07/21/sim-cards...