VMTech
Discuss a project

Unisoc modem exploit chain enables Android kernel access via VoLTE

Unisoc modem exploit chain enables Android kernel access via VoLTE

SSD Secure Disclosure has published a two-stage exploit chain that can give an attacker full Android kernel access through Unisoc modem firmware after a victim answers a VoLTE video call. The research affects at least the Unisoc T606, T612 and T7250 chipsets, used in devices including the Motorola E13, Realme C33 and Xiaomi Redmi A5.

The August 17, 2026 advisory follows a March disclosure of remote code execution in the same firmware through a malformed SIP video call. SSD says an attacker needs that initial modem-level foothold, control of a private 4G cellular network and an answered incoming video call to complete the chain.

From modem execution to the Android kernel

The privilege-escalation issue is classified as CWE-1189, Improper Isolation of Shared Resources on System-on-a-Chip. No CVE identifier had been assigned when the advisory was published, and SSD said it had received no response after attempting to contact Unisoc through email and LinkedIn.

Once code is running on the modem, the researchers write a full-access configuration to the modem ARM Memory Protection Unit through coprocessor registers. That maps the complete 32-bit physical address space as readable, writable and executable from modem context, including pages containing the Android kernel.

The underlying condition is that the modem processor and application processor share physical memory in the Unisoc SoC, without a hardware-enforced boundary that stops modem-context code from modifying kernel memory. SSD confirmed kernel-level code execution on a test device by observing kernel log output from the injected payload.

Devices tested and patch status

Researchers confirmed the privilege-escalation flaw on a Motorola E13 with the February 2025 security patch and a Xiaomi Redmi A5 with the January 2026 patch. Their proof-of-concept environment used an open-source 4G core network, a software-defined radio for the radio interface and specialised SIM cards.

The August 2026 Android Security Bulletin, released before the disclosure, does not address this privilege-escalation vulnerability, and no Unisoc security bulletin covers it. A separate October 2025 Unisoc advisory, CVE-2025-31718 with a CVSS score of 7.5, concerns modem input validation on the same chipset family, but SSD said it is unclear whether that issue matches the March remote-code-execution disclosure.

Architecture remains central to the risk

Related research makes the shared-memory design relevant beyond this chain. In November 2025, Kaspersky ICS CERT documented the same architectural condition on the Unisoc UIS7862A used in vehicle head units; after separate modem code execution, its researchers also modified the running Android kernel.

Kaspersky described one lateral path involving a hidden Direct Memory Access peripheral as a hardware-level issue not fixable by software. SSD's Memory Protection Unit route is, in principle, addressable through a firmware change, but Unisoc has not committed to one. By contrast, Unisoc patched CVE-2022-20210, a Check Point Research-discovered modem vulnerability, and the fix was distributed through the Android Security Bulletin.

There is currently no available patch or mitigation for device owners. Businesses should inventory Unisoc-based Android devices, monitor manufacturer firmware releases and include modem firmware exposure in mobile-device risk management until an update becomes available.

#androidsecurity#mobilesecurity#volte#firmwaresecurity
Open analytics
On the site 4 views
min read 4 22.08.2026
Instagram

Unisoc modem exploit chain enables Android kernel access via VoLTE

Open the post on Instagram ↗