VMTech
Discuss a project →

Unisoc modem exploit chain enables Android kernel access via VoLTE

Unisoc modem exploit chain enables Android kernel access via VoLTE

SSD Secure Disclosure has published a two-stage exploit chain that can give an attacker full Android kernel access through Unisoc modem firmware after a victim answers a VoLTE video call. The research affects at least the Unisoc T606, T612 and T7250 chipsets, used in devices including the Motorola E13, Realme C33 and Xiaomi Redmi A5.

The August 17, 2026 advisory follows a March disclosure of remote code execution in the same firmware through a malformed SIP video call. SSD says an attacker needs that initial modem-level foothold, control of a private 4G cellular network and an answered incoming video call to complete the chain.

From modem execution to the Android kernel

The privilege-escalation issue is classified as CWE-1189, Improper Isolation of Shared Resources on System-on-a-Chip. No CVE identifier had been assigned when the advisory was published, and SSD said it had received no response after attempting to contact Unisoc through email and LinkedIn.

Once code is running on the modem, the researchers write a full-access configuration to the modem ARM Memory Protection Unit through coprocessor registers. That maps the complete 32-bit physical address space as readable, writable and executable from modem context, including pages containing the Android kernel.

The underlying condition is that the modem processor and application processor share physical memory in the Unisoc SoC, without a hardware-enforced boundary that stops modem-context code from modifying kernel memory. SSD confirmed kernel-level code execution on a test device by observing kernel log output from the injected payload.

Devices tested and patch status

Researchers confirmed the privilege-escalation flaw on a Motorola E13 with the February 2025 security patch and a Xiaomi Redmi A5 with the January 2026 patch. Their proof-of-concept environment used an open-source 4G core network, a software-defined radio for the radio interface and specialised SIM cards.

The August 2026 Android Security Bulletin, released before the disclosure, does not address this privilege-escalation vulnerability, and no Unisoc security bulletin covers it. A separate October 2025 Unisoc advisory, CVE-2025-31718 with a CVSS score of 7.5, concerns modem input validation on the same chipset family, but SSD said it is unclear whether that issue matches the March remote-code-execution disclosure.

Architecture remains central to the risk

Related research makes the shared-memory design relevant beyond this chain. In November 2025, Kaspersky ICS CERT documented the same architectural condition on the Unisoc UIS7862A used in vehicle head units; after separate modem code execution, its researchers also modified the running Android kernel.

Kaspersky described one lateral path involving a hidden Direct Memory Access peripheral as a hardware-level issue not fixable by software. SSD's Memory Protection Unit route is, in principle, addressable through a firmware change, but Unisoc has not committed to one. By contrast, Unisoc patched CVE-2022-20210, a Check Point Research-discovered modem vulnerability, and the fix was distributed through the Android Security Bulletin.

There is currently no available patch or mitigation for device owners. Businesses should inventory Unisoc-based Android devices, monitor manufacturer firmware releases and include modem firmware exposure in mobile-device risk management until an update becomes available.

#androidsecurity#mobilesecurity#volte#firmwaresecurity

Understanding the Unisoc VoLTE video call exploit chain

The reported Unisoc VoLTE vulnerability is a two-stage chain rather than a simple call-triggered takeover. It combines modem-level code execution with insufficient isolation between the modem and Android processors, allowing code already running on the modem to reach kernel memory.

Why the exploit requires two stages

The initial stage provides a foothold in Unisoc modem firmware through a malformed SIP video call. The second stage changes the modem’s memory-protection configuration, exposing the shared physical address space that contains the Android kernel. Completing the demonstrated Unisoc VoLTE video call exploit also requires control of a private 4G network and an answered incoming video call.

  • Stage one establishes code execution in the modem firmware.
  • Stage two uses shared memory to modify the running Android kernel.
  • The demonstrated chain requires a controlled private 4G network.
  • The victim must answer the incoming VoLTE video call.

Affected hardware and patch status

The research covers at least the Unisoc T606, T612 and T7250 chipsets. Kernel access was confirmed on a Motorola E13 with the February 2025 security patch and a Xiaomi Redmi A5 with the January 2026 patch. At the time of the disclosure, the privilege-escalation issue had no assigned CVE and was not covered by an available patch or mitigation.

  • A chipset match indicates potential exposure, not confirmed exploitation.
  • A recent Android patch date alone does not confirm that this flaw is fixed.
  • CVE-2025-31718 is a separate modem issue whose relationship to the earlier disclosure remains unclear.

Practical checks for Android device fleets

Businesses using Android devices can treat this Unisoc VoLTE vulnerability as a firmware and hardware inventory issue. Record device models, chipsets, Android patch levels and manufacturer firmware versions, then monitor vendor releases for an explicit fix rather than assuming a general Android update covers the modem flaw.

  • Identify devices built on the affected Unisoc chipset families.
  • Track modem firmware and Android security updates separately.
  • Monitor manufacturer and Unisoc notices for a specific correction.
  • Include modem firmware exposure in mobile-device risk reviews.

Frequently asked questions

Can an ordinary VoLTE call immediately compromise an Android phone?

The demonstrated chain has additional prerequisites. It requires modem-level code execution, control of a private 4G network and an answered incoming VoLTE video call before the kernel-access stage can be completed.

Which devices were tested for the Unisoc VoLTE exploit?

Researchers confirmed kernel-level execution on a Motorola E13 and a Xiaomi Redmi A5. The affected chipset list also includes the Unisoc T606, T612 and T7250, but this does not establish that every device using them was tested.

Is there a patch for the Unisoc VoLTE vulnerability?

No patch or device-owner mitigation was available at the time covered by the disclosure. Device owners should monitor manufacturer firmware releases and look for an update that explicitly addresses the modem-to-kernel isolation issue.

Open analytics
On the site 66 views
min read 4 22.08.2026
On Instagram 2 views
On Instagram 1 reach
Instagram

Unisoc modem exploit chain enables Android kernel access via VoLTE

Open the post on Instagram ↗