Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Google wants you to use its phones less and its AI more – but who’s buying it?

    August 18, 2026

    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    August 18, 2026

    Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Google wants you to use its phones less and its AI more – but who’s buying it?
    • Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
    • Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more
    • Scientists may have finally proved that “empty” space isn’t really empty
    • How the far right is tightening its grip over the EU – from the inside | Alberto Alemanno
    • Isles of Scilly friendliest place in England, social division research finds | England
    • The Lib Dem dilemma: Cozy up to Burnham or strike out alone?
    • Burnham is choosing jobs over climate security. That’s a big risk | Gaby Hinsliff
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalAug 17, 2026Vulnerability / Mobile Security

    Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker.

    The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the same firmware through a malformed SIP video call. Completing the full chain requires the attacker to control a private 4G cellular network and the victim to answer the incoming video call.

    “We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response,” SSD Secure Disclosure said in its advisory.

    The March 2026 disclosure carried the same statement. The research was carried out by an independent security researcher using the handle 0x50594d.

    The privilege-escalation vulnerability is classified as CWE-1189, Improper Isolation of Shared Resources on System-on-a-Chip, and no CVE identifier has been assigned as of publication.

    The flaw resides in the modem firmware shared by at least three Unisoc chipsets, among them the T606 found in the Motorola E13, the T612 found in the Realme C33, and the T7250 found in the Xiaomi Redmi A5.

    Cybersecurity

    Unisoc, a Shanghai-based chipmaker formerly known as Spreadtrum, supplies components to brands including Motorola, Realme, and Xiaomi for devices sold across more than 140 countries, according to the advisory.

    Researchers confirmed the privilege-escalation flaw on a Motorola E13 carrying a February 2025 security patch and on a Xiaomi Redmi A5 carrying a January 2026 patch.

    Running the complete chain requires a modem-level foothold from the March 2026 RCE vulnerability first, along with attacker-controlled VoLTE infrastructure and a victim who answers the incoming video call.

    The researchers built their proof-of-concept environment using an open-source 4G core network, a software-defined radio for the 4G radio interface, and specialized SIM cards.

    Once code is running on the modem, the privilege-escalation step works by writing a full-access configuration to the modem’s ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable, and executable from modem context, including the pages where the Android kernel resides.

    The condition making this possible is a shared physical memory space between the modem processor and the application processor within the Unisoc SoC, with no hardware-enforced boundary preventing modem-context code from modifying kernel memory.

    Researchers confirmed kernel-level code execution on a test device by observing kernel log output showing that the injected payload had run.

    The August 2026 Android Security Bulletin, published before this disclosure, does not address the privilege-escalation vulnerability, and no UNISOC security bulletin covers it.

    A separate UNISOC advisory from October 2025, CVE-2025-31718 (CVSS score: 7.5), describes a modem input-validation flaw on the same chipset family, though it’s not clear whether it corresponds to the March 2026 SSD disclosure.

    Cybersecurity

    Device owners currently have no available patch or mitigation and should watch for a firmware update from their device manufacturer.

    The disclosure follows independent research published in November 2025 by Kaspersky ICS CERT, which documented the same architectural condition on a different Unisoc chip, the UIS7862A, found in vehicle head units. After gaining modem code execution via a separate vulnerability, the Kaspersky team was also able to reach and modify the running Android kernel by exploiting the modem and application processor’s shared physical address space.

    Kaspersky described one of its lateral movement paths, involving a hidden Direct Memory Access peripheral, as a hardware-level issue not fixable through a software update. The Memory Protection Unit route used in the SSD chain is in principle addressable through a firmware change, though no such update has been committed to by UNISOC.

    A coordinated Unisoc modem vulnerability uncovered by Check Point Research in 2022, CVE-2022-20210, was patched by UNISOC and distributed through the Android Security Bulletin. The two currently disclosed vulnerabilities carry no such assurance.

    access Android Attackers call chain exploit Full Give Kernel Unisoc video VoLTE
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    You can turn an old Android into a Raspberry Pi alternative – but know this first

    ByteDance Seed and Tsinghua AIR Introduces CUDA Agent: A Large-Scale Agentic RL System for CUDA Kernel Generation

    How MCP Servers Can Expose Enterprise Secrets

    Turf War Between Claude Agents Leads to Self-Replicating Malware

    Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Google wants you to use its phones less and its AI more – but who’s buying it?

    August 18, 2026

    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    August 18, 2026

    Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more

    August 18, 2026

    Scientists may have finally proved that “empty” space isn’t really empty

    August 18, 2026
    Latest Posts

    Wisconsin’s Democratic primary for governor: a look at the 5 remaining

    July 27, 2026

    UK CO2 storage project that will reuse existing infrastructure secures lease

    July 27, 2026

    Bangladesh shipbreakers push back against stricter environmental standards

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Google wants you to use its phones less and its AI more – but who’s buying it?

    August 18, 2026

    Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

    August 18, 2026

    Solana treasury firm cuts shares 700-for-1 but leaves room for nearly 100 billion more

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.