Unisoc modem exploit chain reaches the Android kernel through a video call
Researchers at SSD Secure Disclosure published a two-stage exploit chain that gains full Android kernel access on devices using Unisoc modem firmware, triggered by a VoLTE video call. The first stage, disclosed earlier this year, is remote code execution in the modem via a malformed call; the new second stage abuses a memory-isolation weakness in the modem to disable its protections and reach kernel memory. Pulling it off requires the attacker to run a rogue 4G network and the victim to answer the call. The affected firmware is shared across several Unisoc chipsets used in budget phones from brands like Motorola, Realme, and Xiaomi, and there is no fix from the chipmaker.
- Check
- Identify devices using affected Unisoc chipsets in your fleet, and since there is no vendor patch, watch for manufacturer firmware updates and weigh the risk for devices on untrusted cellular networks.
- Affected
- Android devices built on affected Unisoc chipsets, common in budget phones and some embedded and vehicle systems; an attacker on a rogue network can chain a video call into kernel access.
- Fix
- Press device makers for firmware updates, treat the modem as an untrusted boundary in device designs, and restrict exposure to rogue cellular networks where possible, since the attack needs an answered call.