Security1 distinct publisher3 min readUpdated
SSD Secure Disclosure says a Unisoc modem flaw lets attackers cross from modem code execution into kernel memory. There is no patch, no CVE, and no vendor response.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
SSD Secure Disclosure published the second stage of a Unisoc exploit chain on August 17, 2026: modem code execution obtained through a malformed SIP video call in March 2026, then a privilege escalation that gives full Android kernel access, with no fix from the chipset maker [1][2]. For anyone operating a fleet of entry-level handsets, this is a defect that cannot be closed by patch management, because there is nothing to install [17].
The escalation is not a memory-corruption trick. Once code runs on the modem, the researchers write a full-access configuration into the modem's ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable and executable from modem context, including the pages holding the Android kernel [12]. That works because the modem processor and the application processor share physical memory inside the Unisoc SoC with no hardware-enforced boundary stopping modem-context code from rewriting kernel memory [13]. Kernel-level execution was confirmed by observing kernel log output from the injected payload [14].
The cost of entry is real but not exotic. The full chain needs the March 2026 modem foothold, attacker-controlled VoLTE infrastructure, and a victim who answers the incoming video call [3]. The proof-of-concept environment was an open-source 4G core network, a software-defined radio for the radio interface, and specialised SIM cards [11]. That profile points at targeted, proximity-bound operations rather than commodity crime, and it means the only variables an operator controls are which devices exist in the estate and where they are carried.
The affected firmware is shared across at least three Unisoc chipsets: the T606 in the Motorola E13, the T612 in the Realme C33, and the T7250 in the Xiaomi Redmi A5 [8]. Unisoc, the Shanghai-based chipmaker formerly called Spreadtrum, supplies Motorola, Realme and Xiaomi for devices sold in more than 140 countries, according to the advisory [9]. Patch currency is no defence: the flaw was confirmed on a Motorola E13 at the February 2025 patch level and on a Xiaomi Redmi A5 at the January 2026 level [10], the latter roughly seven months before disclosure [22].
The paperwork is missing as well. The bug is classified as CWE-1189, improper isolation of shared resources on a system-on-chip, with no CVE assigned at publication [7]. The August 2026 Android Security Bulletin, issued before the disclosure, does not cover it, and no UNISOC bulletin does either [15]. SSD says it tried email and LinkedIn and received no response from the vendor, the same statement it made in March [4][5]; the research is credited to an independent researcher using the handle 0x50594d [6]. Compare 2022, when a Unisoc modem flaw found by Check Point Research, CVE-2022-20210, was fixed by UNISOC and shipped through the Android Security Bulletin [21].
The architecture problem has been documented before. Kaspersky ICS CERT reported in November 2025 that the same shared-address-space condition on the Unisoc UIS7862A, used in vehicle head units, allowed modem code to reach and modify the running Android kernel [18]; one of its lateral paths, via a hidden DMA peripheral, was described as a hardware-level issue not fixable in software [19].
What to watch: a firmware update from device manufacturers, which is currently the only remedy on offer [17]; a CVE assignment or a UNISOC bulletin, since the MPU route is in principle fixable in firmware but no update has been committed [20][7]; and whether the October 2025 UNISOC advisory CVE-2025-31718, CVSS 7.5, turns out to describe the March RCE, which the source says is unclear [16]. In the meantime, the actionable work is inventory: identify T606, T612 and T7250 devices [8] and decide what those handsets are allowed to hold.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
SSD Secure Disclosure published a two-stage exploit chain achieving full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker; the advisory was published August 17, 2026.
The August 2026 advisory is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the same firmware through a malformed SIP video call.
Running the complete chain requires the modem-level foothold from the March 2026 RCE vulnerability, attacker-controlled VoLTE infrastructure including a private 4G cellular network, and a victim who answers the incoming video call.
SSD Secure Disclosure said in its advisory: "We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response."
The March 2026 disclosure carried the same statement about unsuccessful vendor contact.
The research was carried out by an independent security researcher using the handle 0x50594d.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed technical account, single publisher, primary advisory not in cluster
The mechanism is described concretely enough to evaluate (MPU reconfiguration through coprocessor registers, shared modem/AP physical address space, kernel execution verified by kernel log output) and it is architecturally corroborated by independently published Kaspersky ICS CERT work on another Unisoc part. Against that, every claim reaches the cluster through one publisher, and the two cluster items are the same article text republished, so there is no cross-outlet check, no vendor or OEM response, no third-party reproduction, and no CVE or severity score for the new flaw.
Wide exposed device base, no observed exploitation or fix uptake
Exposure is broad on the face of the reporting: the flaw sits in modem firmware shared by at least three Unisoc chipsets found in current low-cost handsets from Motorola, Realme and Xiaomi, with the advisory citing distribution across more than 140 countries, and it was confirmed on two retail devices at recent patch levels. What is absent is any evidence of exploitation in the wild, any count of affected units, and any patch, bulletin entry or OEM rollout to measure remediation against, which keeps the measured value well below the exposure ceiling.
Slightly overstated by framing, tempered by disclosed preconditions
The headline framing of an answered video call yielding full kernel access runs ahead of the operational reality, which requires a prior modem RCE foothold, attacker-controlled VoLTE infrastructure including a private 4G network, and user interaction. The reporting itself discloses those preconditions and the lab-only proof-of-concept rig, which keeps the gap small rather than large; the underlying isolation defect and the absence of any patch or CVE are, if anything, understated relative to their long-term significance.
Disclosure-program publicity with no vendor counterweight
The account originates with a vulnerability disclosure program publishing its own two-part research, credited to a pseudonymous independent researcher, and it is reinforced by a commercial security vendor's prior research; each party benefits reputationally from a dramatic chain. Because the chipmaker reportedly never responded to contact attempts and no OEM comment appears, there is no adversarial party to test framing or severity. The publisher's own commercial incentives, funding, or any relationship to the disclosing parties are not disclosed in the supplied material, so this is scored on visible sourcing structure only.
Internally consistent and dated, but single-publisher and vendor-unconfirmed
Dates, chipsets, patch levels, classification and verification method are specific and mutually consistent across the cluster, and the architectural claim has independent prior support. Confidence is held near the middle because the cluster contains one publisher (twice), the primary advisory is not itself a supplied source, no vendor or OEM has confirmed or contested the finding, and the relationship between the March disclosure and CVE-2025-31718 is explicitly unresolved.
security
Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing1 distinct publisher
science
Cursor runs a repository's own git.exe on Windows, and has done for months1 distinct publisher
build
A 160MB Attacker Workspace Is the First Real Parts List for Autonomous Intrusion1 distinct publisher
security
One console, two businesses: Broadcom says Jewelbug runs espionage and crypto fraud together1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 17, 2026