Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

August 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: Medium
Victim: Users of Unisoc-powered Android devices
Incident: Discovery of a zero-day exploit chain in Unisoc modem firmware allowing remote kernel access.
Impact: Full Android kernel compromise, allowing complete device takeover.
Attacker: Unidentified threat actors
Analysis: Researchers discovered a two-stage exploit that leverages a modem-level RCE followed by a privilege escalation flaw (CWE-1189). The vulnerability stems from a lack of hardware-enforced memory isolation between the modem processor and the application processor. Since the vendor remains non-responsive, devices from brands like Motorola, Realme, and Xiaomi are currently unprotected.
Recommendations: Monitor for anomalous VoLTE or SIP traffic patterns within cellular environments.; Implement strict device integrity checks to detect unauthorized kernel modifications.; Advise high-risk users to limit interactions with unknown callers on affected Unisoc hardware.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *