Researchers disclosed a two-stage exploit chain in Unisoc modem firmware that can turn a VoLTE video call into full Android kernel access on vulnerable devices. The attack combines a previously published remote code execution flaw in the UNISOC T612 modem stack with a newly revealed privilege-escalation weakness caused by inadequate isolation between the modem and application processor. After a target answers an incoming video call, code running in the modem context can map and alter kernel memory because both components share physical memory without a hardware-enforced boundary.
SSD Secure Disclosure said the issue was validated on devices including the Motorola E13 and Xiaomi Redmi A5, and reported that the flaw has no CVE, no vendor response, no patch, and no published mitigation. The attack is not trivial because it requires the adversary to operate a private 4G network, but the technique echoes prior modem-to-system compromise research, including Kaspersky ICS CERT’s demonstration of remotely pivoting from a vehicle modem into a head unit. Neither the August 2026 Android Security Bulletin nor any UNISOC bulletin reportedly addresses the newly disclosed escalation bug.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-17, SSD Secure Disclosure published a second-stage privilege-escalation exploit affecting vulnerable Unisoc modem firmware that can achieve full Android kernel access via a VoLTE video call. The issue stems from improper isolation of shared SoC resources, and SSD said Unisoc had not responded to outreach and that no CVE, patch, mitigation, Android bulletin entry, or Unisoc bulletin covered the flaw at disclosure time.
In March 2026, SSD Secure Disclosure disclosed the first stage of the exploit chain: a remote code execution vulnerability in Unisoc modem firmware triggered through a malformed SIP video call. This modem-side RCE later became the initial stage used in the full exploit chain.
In November 2025, Kaspersky ICS CERT published research on the Unisoc UIS7862A used in vehicle head units, describing the shared physical memory architecture between the modem and application processor. It also demonstrated that after achieving modem code execution through a separate flaw, an attacker could modify the running Android kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourceinfosecurity-magazine.com
Open sourcethehackernews.com
Open sourcessd-disclosure.com
Open sourceics-cert.kaspersky.com
Open sourcessd-disclosure.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.