← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Unisoc VoLTE Exploit Chain Grants Full Android Kernel Access, No Fix Available

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two-stage exploit chain achieves full Android kernel access.
  • Vulnerability affects Unisoc modem firmware via VoLTE video calls.
  • No fix has been released by Unisoc for this flaw.
  • Impacts devices from Motorola, Realme, and Xiaomi.

Exploit Chain Details

SSD Secure Disclosure researchers have released a two-stage exploit chain that can grant full Android kernel access on devices equipped with Unisoc modem firmware. This exploit is initiated through a VoLTE video call, building on a previous remote code execution (RCE) disclosure from March 2026 involving malformed SIP video calls in the same firmware.

Vulnerability and Affected Devices

The privilege-escalation vulnerability, classified as CWE-1189, stems from improper isolation of shared resources on the system-on-a-chip. It resides in modem firmware shared by at least three Unisoc chipsets: the T606 (found in Motorola E13), the T612 (in Realme C33), and the T7250 (in Xiaomi Redmi A5). Unisoc, a Shanghai-based chipmaker, supplies components to brands like Motorola, Realme, and Xiaomi for devices sold in over 140 countries.

Exploitation Requirements

To execute the full exploit chain, an attacker needs to control a private 4G cellular network and the victim must answer the incoming video call. The process requires a modem-level foothold from the March 2026 RCE vulnerability, attacker-controlled VoLTE infrastructure, and a victim answering the call. Researchers confirmed the flaw on a Motorola E13 with a February 2025 security patch and a Xiaomi Redmi A5 with a January 2026 patch.

Technical Mechanism

Once code is running on the modem, the privilege-escalation step involves writing a full-access configuration to the modem's ARM Memory Protection Unit via coprocessor registers. This action maps the entire 32-bit physical address space as readable, writable, and executable from the modem context, including the memory pages where the Android kernel resides. This is possible due to a shared physical memory space between the modem processor and the application processor.

Lack of Vendor Response

SSD Secure Disclosure has stated that they have attempted to contact Unisoc through multiple channels, including email and LinkedIn, but have not received any response regarding the vulnerability. This lack of communication was also noted in their March 2026 disclosure concerning the initial RCE vulnerability.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~15 min · 13 stories · Aug 17

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that allows full Android kernel access on devices using Unisoc modem firmware via a VoLTE video call. The chipset maker has not provided a fix for this vulnerability, which affects devices from Motorola, Realme, and Xiaomi.