Video Call Exploit Chains Two Flaws in Unisoc Modems

Security researchers have uncovered a new vulnerability in Unisoc modem firmware that, when combined with an existing flaw, allows an attacker to take control of an Android device by exploiting its cellular connectivity. This attack chain is particularly insidious because it requires only that the victim answer a video call on their affected phone.

The vulnerability was discovered by researchers at SSD Secure Disclosure, who found that by chaining two flaws in Unisoc’s T612 modem firmware, they could gain privileged access to the Android kernel on affected devices. The first flaw is a previously disclosed remote code execution (RCE) vulnerability that allows an attacker to inject malicious code into the modem. The second flaw is a memory-isolation weakness in the modem’s memory protection unit, which enables an attacker with already compromised access to escalate privileges and gain kernel-level access.

To execute this attack chain, an attacker would first need to deliver a malicious payload to the phone’s modem via the RCE vulnerability. They could then trigger the exploit by making a video call to the device, which the victim must answer for the attack to work. This second stage of the attack reassembles the fragmented payload and executes code that disables the modem’s memory protections, allowing the attacker to access Android kernel memory.

SSD Secure demonstrated this attack chain in a controlled setting against a Realme C33 smartphone running the affected firmware. They also confirmed the vulnerability on a Xiaomi Redmi A5 and a Motorola E13, although it is unclear at present whether other manufacturers’ devices are also affected. Unisoc Technologies Co. Ltd., the Chinese semiconductor design company responsible for developing the chipsets, has not responded to requests for comment.

The fact that this attack chain relies on the victim answering a video call makes it all the more insidious. Cellular modems have long been recognized as a significant and often remotely reachable attack surface, with previous research demonstrating vulnerabilities in Unisoc’s baseband and Samsung’s Exynos modems.

For Android users who rely on cellular connectivity, this research serves as a timely reminder to exercise caution when receiving unsolicited video calls or messages. In the event that your phone is affected by this vulnerability, it may be possible for an attacker to gain control of your device without your knowledge or consent. To mitigate this risk, it’s essential to keep your operating system and firmware up-to-date with the latest security patches and to be vigilant when receiving suspicious calls or messages.

Ultimately, this research highlights the ongoing threat posed by vulnerabilities in cellular modem firmware. As we increasingly rely on our devices for communication and connectivity, it’s essential that manufacturers prioritize the development of secure and robust modems that can withstand even the most sophisticated attacks.


Source: Dark Reading — 2026-08-17