HackMyIP
← Back to News
2026-08-17 The Hacker News

Unisoc VoLTE Exploit Chain Gives Attackers Full Android Kernel Access

VulnerabilityZero-DaySupply Chain

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices powered by Unisoc modem firmware, triggered through a single answered VoLTE video call. The August 17, 2026 advisory follows a March 2026 disclosure of remote code execution in the same firmware via a malformed SIP call, but adds a privilege-escalation flaw classified as CWE-1189 — Improper Isolation of Shared Resources on System-on-a-Chip — that escalates modem-level execution into full control of the application processor's kernel. No CVE has been assigned and no patch is available from Unisoc, leaving potentially millions of budget Android devices exposed.

The attack requires the attacker to operate a private 4G cellular network; the researchers built their proof-of-concept using an open-source 4G core network, a software-defined radio for the radio interface, and programmable SIM cards. Once the victim answers the incoming VoLTE video call, the March 2026 RCE lands code execution in the modem. The new step then writes a permissive configuration to the modem's ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable, and executable from modem context. Because the Unisoc SoC shares physical memory between modem and application processor with no hardware-enforced boundary, the injected payload can directly modify the pages where the Android kernel resides — kernel log output confirmed successful execution on a test device. Users concerned about their exposure on affected hardware can run a quick privacy checkup on their device, while those tracking the affected vendors can verify their asset footprint via a WHOIS lookup.

The flaw resides in modem firmware shared by at least three Unisoc chipsets: the T606 in the Motorola E13, the T612 in the Realme C33, and the T7250 in the Xiaomi Redmi A5. Researchers confirmed successful exploitation against a Motorola E13 carrying a February 2025 security patch and a Xiaomi Redmi A5 carrying a January 2026 patch, indicating that recent Android security bulletins do not mitigate the issue. Unisoc, the Shanghai-based chipmaker formerly known as Spreadtrum, supplies components to brands including Motorola, Realme, and Xiaomi for devices sold across more than 140 countries. SSD Secure Disclosure says it attempted to reach Unisoc through both email and LinkedIn on multiple occasions before disclosure but received no response — the same statement appeared in the March 2026 advisory. The research was carried out by an independent researcher using the handle 0x50594d.

The August 2026 Android Security Bulletin was published before this disclosure and does not address the privilege-escalation vulnerability, and no Unisoc security bulletin covered it either. With no firmware fix forthcoming and no hardware memory-isolation barrier between modem and application processor on the affected chipsets, the devices remain vulnerable to any attacker with the means to operate a rogue 4G base station. Network operators and security teams tracking the broader LTE attack surface can audit adjacent infrastructure exposure using a port scanner to identify rogue or unexpected cellular-adjacent services on their networks.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Port Scanner →DNS Leak Test →Privacy Checkup →

Related Guides

Learn the background behind this story:

Signs your router is hacked →Wi-Fi security checklist →How to find your router's IP →