Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Swati KhandelwalAug 17, 2026Vulnerability / Cellular Safety

Safety researchers at SSD Safe Disclosure have printed a two-stage exploit chain that achieves full Android kernel entry on units operating Unisoc modem firmware by means of a VoLTE video name, with no repair from the chipset maker.

The advisory, printed August 17, 2026, is the second stage of a series that started in March 2026, when SSD disclosed remote code execution in the identical firmware by means of a malformed SIP video name. Finishing the complete chain requires the attacker to regulate a non-public 4G mobile community and the sufferer to reply the incoming video name.

“We have now tried to achieve out to the seller by means of a number of channels (electronic mail and LinkedIn) however haven’t been capable of obtain any response,” SSD Safe Disclosure stated in its advisory.

The March 2026 disclosure carried the identical assertion. The analysis was carried out by an unbiased safety researcher utilizing the deal with 0x50594d.

The privilege-escalation vulnerability is assessed as CWE-1189, Improper Isolation of Shared Sources on System-on-a-Chip, and no CVE identifier has been assigned as of publication.

The flaw resides within the modem firmware shared by a minimum of three Unisoc chipsets, amongst them the T606 discovered within the Motorola E13, the T612 discovered within the Realme C33, and the T7250 discovered within the Xiaomi Redmi A5.

Unisoc, a Shanghai-based chipmaker previously referred to as Spreadtrum, provides parts to manufacturers together with Motorola, Realme, and Xiaomi for units offered throughout greater than 140 nations, in keeping with the advisory.

Researchers confirmed the privilege-escalation flaw on a Motorola E13 carrying a February 2025 safety patch and on a Xiaomi Redmi A5 carrying a January 2026 patch.

Working the entire chain requires a modem-level foothold from the March 2026 RCE vulnerability first, together with attacker-controlled VoLTE infrastructure and a sufferer who solutions the incoming video name.

The researchers constructed their proof-of-concept atmosphere utilizing an open-source 4G core community, a software-defined radio for the 4G radio interface, and specialised SIM playing cards.

As soon as code is operating on the modem, the privilege-escalation step works by writing a full-access configuration to the modem’s ARM Reminiscence Safety Unit by means of coprocessor registers, mapping the complete 32-bit bodily handle area as readable, writable, and executable from modem context, together with the pages the place the Android kernel resides.

The situation making this potential is a shared bodily reminiscence area between the modem processor and the appliance processor inside the Unisoc SoC, with no hardware-enforced boundary stopping modem-context code from modifying kernel reminiscence.

Researchers confirmed kernel-level code execution on a check machine by observing kernel log output exhibiting that the injected payload had run.

The August 2026 Android Safety Bulletin, printed earlier than this disclosure, doesn’t handle the privilege-escalation vulnerability, and no UNISOC safety bulletin covers it.

A separate UNISOC advisory from October 2025, CVE-2025-31718 (CVSS rating: 7.5), describes a modem input-validation flaw on the identical chipset household, although it is not clear whether or not it corresponds to the March 2026 SSD disclosure.

Machine house owners presently don’t have any out there patch or mitigation and will look ahead to a firmware replace from their machine producer.

The disclosure follows independent research printed in November 2025 by Kaspersky ICS CERT, which documented the identical architectural situation on a distinct Unisoc chip, the UIS7862A, present in automobile head models. After gaining modem code execution through a separate vulnerability, the Kaspersky group was additionally capable of attain and modify the operating Android kernel by exploiting the modem and utility processor’s shared bodily handle area.

Kaspersky described one among its lateral motion paths, involving a hidden Direct Reminiscence Entry peripheral, as a hardware-level situation not fixable by means of a software program replace. The Reminiscence Safety Unit route used within the SSD chain is in precept addressable by means of a firmware change, although no such replace has been dedicated to by UNISOC.

A coordinated Unisoc modem vulnerability uncovered by Check Point Research in 2022, CVE-2022-20210, was patched by UNISOC and distributed by means of the Android Safety Bulletin. The 2 presently disclosed vulnerabilities carry no such assurance.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *