SSD Secure Disclosure researchers have released a two-stage exploit chain that can grant full Android kernel access on devices equipped with Unisoc modem firmware. This exploit is initiated through a VoLTE video call, building on a previous remote code execution (RCE) disclosure from March 2026 involving malformed SIP video calls in the same firmware.
The privilege-escalation vulnerability, classified as CWE-1189, stems from improper isolation of shared resources on the system-on-a-chip. It resides in modem firmware shared by at least three Unisoc chipsets: the T606 (found in Motorola E13), the T612 (in Realme C33), and the T7250 (in Xiaomi Redmi A5). Unisoc, a Shanghai-based chipmaker, supplies components to brands like Motorola, Realme, and Xiaomi for devices sold in over 140 countries.
To execute the full exploit chain, an attacker needs to control a private 4G cellular network and the victim must answer the incoming video call. The process requires a modem-level foothold from the March 2026 RCE vulnerability, attacker-controlled VoLTE infrastructure, and a victim answering the call. Researchers confirmed the flaw on a Motorola E13 with a February 2025 security patch and a Xiaomi Redmi A5 with a January 2026 patch.
Once code is running on the modem, the privilege-escalation step involves writing a full-access configuration to the modem's ARM Memory Protection Unit via coprocessor registers. This action maps the entire 32-bit physical address space as readable, writable, and executable from the modem context, including the memory pages where the Android kernel resides. This is possible due to a shared physical memory space between the modem processor and the application processor.
SSD Secure Disclosure has stated that they have attempted to contact Unisoc through multiple channels, including email and LinkedIn, but have not received any response regarding the vulnerability. This lack of communication was also noted in their March 2026 disclosure concerning the initial RCE vulnerability.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that allows full Android kernel access on devices using Unisoc modem firmware via a VoLTE video call. The chipset maker has not provided a fix for this vulnerability, which affects devices from Motorola, Realme, and Xiaomi.