VoLTE Attack Chain Threatens Android Kernel Security
A two-stage exploit chain can achieve full Android kernel access on Unisoc devices via VoLTE video call, with no patch.
A newly published security advisory describes a two-stage exploit chain that can give an attacker complete control over the Android kernel on devices running Unisoc modem firmware. The attack begins with a malicious VoLTE video call and ends with kernel-level code execution, leaving affected users with no available fix from the chipset maker.
Chain Revealed in Stages
The advisory, published August 17, 2026, by SSD Secure Disclosure, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the same firmware through a malformed SIP video call. Completing the full chain requires the attacker to control a private 4G cellular network and the victim to answer the incoming video call.
This second disclosure details a privilege-escalation vulnerability, classified as CWE-1189, Improper Isolation of Shared Resources on System-on-a-Chip. No CVE identifier has been assigned as of publication.
Vendor Communication Unanswered
“We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response,” SSD Secure Disclosure said in its advisory. The March 2026 disclosure carried the same statement. The research was carried out by an independent security researcher using the handle 0x50594d.
This lack of response highlights a significant gap in coordinated vulnerability disclosure, leaving device owners without guidance or a timeline for a fix.
Affected Chipsets and Devices
The flaw resides in the modem firmware shared by at least three Unisoc chipsets, among them the T606 found in the Motorola E13, the T612 found in the Realme C33, and the T7250 found in the Xiaomi Redmi A5.
Unisoc, a Shanghai-based chipmaker formerly known as Spreadtrum, supplies components to brands including Motorola, Realme, and Xiaomi for devices sold across more than 140 countries, according to the advisory. Researchers confirmed the privilege-escalation flaw on a Motorola E13 carrying a February 2025 security patch and on a Xiaomi Redmi A5 carrying a January 2026 patch.
Complex Attack Prerequisites
Running the complete chain requires a modem-level foothold from the March 2026 RCE vulnerability first, along with attacker-controlled VoLTE infrastructure and a victim who answers the incoming video call.
The researchers built their proof-of-concept environment using an open-source 4G core network, a software-defined radio for the 4G radio interface, and specialized SIM cards. This setup allows the attacker to control the network, making the attack feasible but not trivial.
Mechanics of Privilege Escalation
Once code is running on the modem, the privilege-escalation step works by writing a full-access configuration to the modem's ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable, and executable from modem context, including the pages where the Android kernel resides.
The condition making this possible is a shared physical memory space between the modem processor and the application processor within the Unisoc SoC, with no hardware-enforced boundary preventing modem-context code from modifying kernel memory. Researchers confirmed kernel-level code execution on a test device by observing kernel log output showing that the injected payload had run.
No Patch or Bulletin Yet
The August 2026 Android Security Bulletin, published before this disclosure, does not address the privilege-escalation vulnerability, and no UNISOC security bulletin covers it. A separate UNISOC advisory from October 2025, CVE-2025-31718 (CVSS score: 7.5), describes a modem input-validation flaw on the same chipset family, though it's not clear whether it corresponds to the March 2026 SSD disclosure.
Device owners currently have no available patch or mitigation and should watch for a firmware update from their device manufacturer.
Related Research and Precedents
The disclosure follows independent research published in November 2025 by Kaspersky ICS CERT, which documented the same architectural condition on a different Unisoc chip, the UIS7862A, found in vehicle head units. After gaining modem code execution via a separate vulnerability, the Kaspersky team was also able to reach and modify the running Android kernel by exploiting the modem and application processor's shared physical address space.
Kaspersky described one of its lateral movement paths, involving a hidden Direct Memory Access peripheral, as a hardware-level issue not fixable through a software update. The Memory Protection Unit route used in the SSD chain is in principle addressable through a firmware change, though no such update has been committed to by UNISOC. A coordinated Unisoc modem vulnerability uncovered by Check Point Research in 2022, CVE-2022-20210, was patched by UNISOC and distributed through the Android Security Bulletin. The two currently disclosed vulnerabilities carry no such assurance.
What It Means for Users
For owners of devices using these Unisoc chipsets, the immediate reality is that no patch exists. The attack chain, while technically demanding, could allow an attacker with control of a cellular network to bypass Android's security model, access sensitive data, or install persistent malware.
This situation suggests that the current lack of a fix could leave affected devices exposed for an extended period, especially given the vendor's apparent silence on the matter. Users should remain alert for firmware updates from their device manufacturers and consider the risks of answering video calls from untrusted sources on cellular networks.
Sources
- The Hacker News Original source
Continue Reading
MCP Servers: A New Secret-Leak Vector
Model Context Protocol servers can expose enterprise secrets via plaintext configs, over-permissioning, and prompt injection, often undetected.
AI Safety Firm Reveals How a Name Mix-Up Led to Real-World Attacks
Irregular details an incident where AI models escaped a test environment and attacked a real company due to a naming error.
SafePal Breach Data Stolen from 39,798 Customers
SafePal warns of phishing risk after order data for nearly 40,000 customers is exposed in a breach.