Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

A critical vulnerability has been discovered in the VoLTE (Voice over LTE) implementation of Unisoc’s Android-based chipsets, allowing attackers to gain full kernel access and potentially seize control of affected devices. This exploit chain, which affects a wide range of devices, has significant implications for users’ security and privacy.

The vulnerability, revealed by researchers, lies in the way VoLTE calls are handled on devices equipped with Unisoc’s chipsets. When an attacker initiates a malicious VoLTE call to a victim’s device, they can exploit a sequence of vulnerabilities that ultimately grants them access to the Android kernel. This level of control allows attackers to execute arbitrary code, install malware, and even gain root privileges, effectively rendering the device vulnerable to further exploitation.

The affected devices span multiple manufacturers, including those using Unisoc chipsets in their handsets. While the specific impact on users will depend on the individual device’s configuration and security measures, it is essential to note that this vulnerability can be exploited remotely, making it a particularly insidious threat. Attackers do not require physical access or any prior exploitation of the device; they can launch the attack from anywhere with an internet connection.

The exploit chain works by manipulating the VoLTE call setup process, which typically involves various communication protocols and interactions between different components within the Android system. By carefully crafted manipulation of these interactions, attackers can bypass critical security checks and gain access to sensitive areas of the kernel. This is made possible due to a combination of factors, including issues with permission handling, buffer overflows, and privilege escalation vulnerabilities.

The severity of this vulnerability lies not only in its potential for exploitation but also in its widespread impact on users. Given that VoLTE calls are becoming increasingly common, the likelihood of an attack being launched against an unsuspecting user is higher than ever. Furthermore, the fact that attackers can gain full kernel access means they have a nearly unrestricted ability to manipulate the device’s behavior and execute malicious code.

The discovery of this vulnerability serves as a stark reminder of the importance of regular security updates, rigorous testing, and thorough analysis of software components in modern computing environments. As we continue to rely on increasingly complex systems and interconnected devices, it is crucial that manufacturers and developers prioritize robust security measures and proactive threat monitoring to mitigate such vulnerabilities before they can be exploited by attackers.


Source: The Hacker News — 2026-08-17