Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
- ID
- 14780
- Status
- summarized
- Published
- 17 Aug 2026, 6:52 PM
- Fetched
- 17 Aug 2026, 8:47 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 17 Aug 2026, 8:50 PM
- Tags
- Audience
- developers
What happened
Security researchers at SSD Secure Disclosure published a two-stage exploit chain achieving full Android kernel access on devices with Unisoc modem firmware via a VoLTE video call, with no fix or response from the vendor. The chain requires an attacker-controlled private 4G network and the victim answering the call, affecting at least three Unisoc chipsets (T606, T612, T7250) found in budget phones like the Motorola E13, Realme C33, and Xiaomi Redmi A5.
Why it matters
This is a niche mobile security vulnerability requiring attacker-controlled cellular infrastructure, so most builders have no action to take. The only practical takeaway: if you deploy or support apps on budget Android fleets using Unisoc chipsets (common in Southeast Asian entry-level devices), there is no vendor patch available and no CVE assigned as of August 2026, so device-level mitigations or fleet replacement may be the only options.
Discussion angle
Whether unpatched Unisoc-based budget Android devices in Southeast Asian markets pose a realistic supply-chain risk for any apps or services this audience ships, given the exploit requires attacker-controlled 4G infrastructure.