Skip to content

Security1 publisher3 min readPublished

Unpatched Unisoc chain turns an answered video call into Android kernel access

SSD Secure Disclosure says a Unisoc modem flaw lets attackers cross from modem code execution into kernel memory. There is no patch, no CVE, and no vendor response.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • SSD Secure Disclosure published a two-stage exploit chain achieving full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker; the advisory was published August 17, 2026.
  • The August 2026 advisory is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the same firmware through a malformed SIP video call.
  • Running the complete chain requires the modem-level foothold from the March 2026 RCE vulnerability, attacker-controlled VoLTE infrastructure including a private 4G cellular network, and a victim who answers the incoming video call.
  • SSD Secure Disclosure said in its advisory: "We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response."
  • The March 2026 disclosure carried the same statement about unsuccessful vendor contact.

Compiled by The WatchSomething wrong?How this is made

Why it matters

SSD Secure Disclosure published the second stage of a Unisoc exploit chain on August 17, 2026: modem code execution obtained through a malformed SIP video call in March 2026, then a privilege escalation that gives full Android kernel access, with no fix from the chipset maker [1][2]. For anyone operating a fleet of entry-level handsets, this is a defect that cannot be closed by patch management, because there is nothing to install [17].

The escalation is not a memory-corruption trick. Once code runs on the modem, the researchers write a full-access configuration into the modem's ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable and executable from modem context, including the pages holding the Android kernel [12]. That works because the modem processor and the application processor share physical memory inside the Unisoc SoC with no hardware-enforced boundary stopping modem-context code from rewriting kernel memory [13]. Kernel-level execution was confirmed by observing kernel log output from the injected payload [14].

The cost of entry is real but not exotic. The full chain needs the March 2026 modem foothold, attacker-controlled VoLTE infrastructure, and a victim who answers the incoming video call [3]. The proof-of-concept environment was an open-source 4G core network, a software-defined radio for the radio interface, and specialised SIM cards [11]. That profile points at targeted, proximity-bound operations rather than commodity crime, and it means the only variables an operator controls are which devices exist in the estate and where they are carried.

The affected firmware is shared across at least three Unisoc chipsets: the T606 in the Motorola E13, the T612 in the Realme C33, and the T7250 in the Xiaomi Redmi A5 [8]. Unisoc, the Shanghai-based chipmaker formerly called Spreadtrum, supplies Motorola, Realme and Xiaomi for devices sold in more than 140 countries, according to the advisory [9]. Patch currency is no defence: the flaw was confirmed on a Motorola E13 at the February 2025 patch level and on a Xiaomi Redmi A5 at the January 2026 level [10], the latter roughly seven months before disclosure [22].

The paperwork is missing as well. The bug is classified as CWE-1189, improper isolation of shared resources on a system-on-chip, with no CVE assigned at publication [7]. The August 2026 Android Security Bulletin, issued before the disclosure, does not cover it, and no UNISOC bulletin does either [15]. SSD says it tried email and LinkedIn and received no response from the vendor, the same statement it made in March [4][5]; the research is credited to an independent researcher using the handle 0x50594d [6]. Compare 2022, when a Unisoc modem flaw found by Check Point Research, CVE-2022-20210, was fixed by UNISOC and shipped through the Android Security Bulletin [21].

The architecture problem has been documented before. Kaspersky ICS CERT reported in November 2025 that the same shared-address-space condition on the Unisoc UIS7862A, used in vehicle head units, allowed modem code to reach and modify the running Android kernel [18]; one of its lateral paths, via a hidden DMA peripheral, was described as a hardware-level issue not fixable in software [19].

What to watch: a firmware update from device manufacturers, which is currently the only remedy on offer [17]; a CVE assignment or a UNISOC bulletin, since the MPU route is in principle fixable in firmware but no update has been committed [20][7]; and whether the October 2025 UNISOC advisory CVE-2025-31718, CVSS 7.5, turns out to describe the March RCE, which the source says is unclear [16]. In the meantime, the actionable work is inventory: identify T606, T612 and T7250 devices [8] and decide what those handsets are allowed to hold.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories