Ethical Hacking News
Unisoc VoLTE video call exploit chain: a critical vulnerability exposing full Android kernel access. Learn more about the details of this exploit chain and its potential impact on millions of Android devices worldwide.
Unisoc VoLTE video call exploit chain allows attackers to gain full access to the Android kernel on devices running Unisoc modem firmware. A two-stage exploit chain was published by SSD Secure Disclosure in August 2026, with the first stage disclosed in March 2026. The privilege-escalation vulnerability (CWE-1189) affects at least three Unisoc chipsets, including T606, T612, and T7250. The vulnerability requires a modem-level foothold, attacker-controlled VoLTE infrastructure, and a victim who answers the incoming video call. No CVE identifier has been assigned, and device owners have no available patch or mitigation. The vulnerability affects a wide range of devices running Unisoc modem firmware, with millions of Android devices potentially affected.
The recent disclosure of the Unisoc VoLTE video call exploit chain has sent shockwaves through the cybersecurity community, highlighting a critical vulnerability that allows attackers to gain full access to the Android kernel on devices running Unisoc modem firmware. This alarming revelation has significant implications for the security of millions of Android devices worldwide, and it is essential to understand the details of this exploit chain to appreciate its severity and potential impact.
In August 2026, security researchers at SSD Secure Disclosure published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call. The first stage of the exploit chain was disclosed in March 2026, when SSD disclosed remote code execution in the same firmware through a malformed SIP video call. The second stage of the exploit chain requires the attacker to control a private 4G cellular network and the victim to answer the incoming video call.
The privilege-escalation vulnerability is classified as CWE-1189, Improper Isolation of Shared Resources on System-on-a-Chip, and no CVE identifier has been assigned as of publication. The flaw resides in the modem firmware shared by at least three Unisoc chipsets, including the T606 found in the Motorola E13, the T612 found in the Realme C33, and the T7250 found in the Xiaomi Redmi A5.
Researchers confirmed the privilege-escalation flaw on a Motorola E13 carrying a February 2025 security patch and on a Xiaomi Redmi A5 carrying a January 2026 patch. Running the complete chain requires a modem-level foothold from the March 2026 RCE vulnerability first, along with attacker-controlled VoLTE infrastructure and a victim who answers the incoming video call.
The researchers built their proof-of-concept environment using an open-source 4G core network, a software-defined radio for the 4G radio interface, and specialized SIM cards. Once code is running on the modem, the privilege-escalation step works by writing a full-access configuration to the modem's ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable, and executable from modem context, including the pages where the Android kernel resides.
The condition making this possible is a shared physical memory space between the modem processor and the application processor within the Unisoc SoC, with no hardware-enforced boundary preventing modem-context code from modifying kernel memory. Researchers confirmed kernel-level code execution on a test device by observing kernel log output showing that the injected payload had run.
The August 2026 Android Security Bulletin, published before this disclosure, does not address the privilege-escalation vulnerability, and no UNISOC security bulletin covers it. A separate UNISOC advisory from October 2025, CVE-2025-31718 (CVSS score: 7.5), describes a modem input-validation flaw on the same chipset family, though it's not clear whether it corresponds to the March 2026 SSD disclosure.
Device owners currently have no available patch or mitigation and should watch for a firmware update from their device manufacturer. The disclosure follows independent research published in November 2025 by Kaspersky ICS CERT, which documented the same architectural condition on a different Unisoc chip, the UIS7862A, found in vehicle head units.
The vulnerability is the latest in a series of critical exploits targeting Unisoc modem firmware, with a coordinated Unisoc modem vulnerability uncovered by Check Point Research in 2022 being patched by UNISOC and distributed through the Android Security Bulletin. The two currently disclosed vulnerabilities carry no such assurance, highlighting the ongoing need for vigilance and proactive measures to address these types of vulnerabilities.
The impact of this vulnerability is far-reaching, with millions of Android devices potentially affected. The vulnerability is not limited to specific device models, but rather affects a wide range of devices running Unisoc modem firmware. This makes it essential for device owners to stay informed and take proactive steps to protect their devices from this and other potential vulnerabilities.
In conclusion, the Unisoc VoLTE video call exploit chain represents a critical vulnerability that exposes full Android kernel access. The vulnerability is the result of a shared physical memory space between the modem processor and the application processor within the Unisoc SoC, which allows attackers to modify kernel memory. The lack of a available patch or mitigation highlights the need for device manufacturers to prioritize firmware updates and security patches.
Device owners are urged to exercise caution and monitor their device's firmware for any updates or patches. The disclosure serves as a stark reminder of the ongoing importance of cybersecurity awareness and the need for vigilance in the face of emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/Unisoc-VoLTE-Video-Call-Exploit-Chain-A-Critical-Vulnerability-Exposing-Full-Android-Kernel-Access-ehn.shtml
https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
Published: Mon Aug 17 13:12:35 2026 by llama3.2 3B Q4_K_M