AI Weekly Malaysia

Back to items Summaries

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

ID
14780
Status
summarized
Published
17 Aug 2026, 6:52 PM
Fetched
17 Aug 2026, 8:47 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
17 Aug 2026, 8:50 PM
Tags
Audience
developers

What happened

Security researchers at SSD Secure Disclosure published a two-stage exploit chain achieving full Android kernel access on devices with Unisoc modem firmware via a VoLTE video call, with no fix or response from the vendor. The chain requires an attacker-controlled private 4G network and the victim answering the call, affecting at least three Unisoc chipsets (T606, T612, T7250) found in budget phones like the Motorola E13, Realme C33, and Xiaomi Redmi A5.

Why it matters

This is a niche mobile security vulnerability requiring attacker-controlled cellular infrastructure, so most builders have no action to take. The only practical takeaway: if you deploy or support apps on budget Android fleets using Unisoc chipsets (common in Southeast Asian entry-level devices), there is no vendor patch available and no CVE assigned as of August 2026, so device-level mitigations or fleet replacement may be the only options.

Discussion angle

Whether unpatched Unisoc-based budget Android devices in Southeast Asian markets pose a realistic supply-chain risk for any apps or services this audience ships, given the exploit requires attacker-controlled 4G infrastructure.

Top