Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

A Critical Vulnerability in Unisoc’s VoLTE Technology Exposes Android Devices to Kernel Access Attacks

A devastating exploit chain has been discovered in Unisoc’s Voice over LTE (VoLTE) technology, which is used by numerous Android device manufacturers worldwide. The vulnerability allows attackers to gain full access to the Android kernel, essentially giving them free rein to manipulate and compromise affected devices. This critical flaw affects an estimated 10% of global smartphone sales, putting millions of users at risk.

The exploit chain functions by targeting vulnerabilities in Unisoc’s VoLTE implementation, which is used to enable high-definition voice calls on 4G networks. Specifically, attackers can leverage a sequence of bugs that allow them to elevate privileges from user space to kernel space. This escalation enables the attacker to bypass traditional security mechanisms and access sensitive areas of the device’s operating system.

The vulnerability affects devices running Unisoc’s VoLTE technology, including those manufactured by prominent brands such as Xiaomi, Oppo, and Vivo. The exact number of affected devices is difficult to determine, but industry insiders estimate that around 10% of global smartphone sales – approximately 120 million units in 2025 alone – may be vulnerable.

The exploit chain relies on the fact that VoLTE technology allows for the creation of a special type of process called a “voice socket.” This process enables device manufacturers to implement advanced features such as video calls and voice over internet protocol (VoIP) services. However, researchers have discovered that if an attacker can successfully create a malicious voice socket, they can use it to gain elevated privileges and access the Android kernel.

The impact of this vulnerability is significant, as it allows attackers to execute arbitrary code at the highest level of privilege on affected devices. This means that even if a device’s security measures are in place, an attacker with access to the VoLTE technology can still bypass them and compromise the device’s integrity.

To mitigate this risk, we recommend that all users running Unisoc-based Android devices take immediate action by:

* Regularly updating their operating system and app software

* Disabling VoLTE services when not in use

* Avoiding suspicious or unfamiliar apps that request access to sensitive device features

While the situation is dire, prompt action can help minimize the damage. As always, it’s essential for users to remain vigilant and stay informed about emerging threats to their digital security.


Source: The Hacker News — 2026-08-17