A new exploit chain has been discovered that allows attackers to take control of Android devices by combining two previously known vulnerabilities in Unisoc modems. The attack, which was demonstrated by researchers at SSD Secure Disclosure, can be triggered simply by delivering a malicious payload and convincing the victim to answer a video call on their device.
The flaw hinges on a weakness in the memory protection unit of the Unisoc T612 modem’s firmware, allowing an attacker with access to the modem to escalate privileges and gain kernel-level access on the affected Android device. This is particularly concerning because multiple mobile device manufacturers, including Motorola, Samsung, Realme, Nokia, and ZTE, use Unisoc chipsets in their products.
The researchers found that by chaining this memory isolation weakness with a previously disclosed remote code execution (RCE) vulnerability in the modem’s handling of SIP/SDP data used for video calls, they could execute arbitrary code on the device. The attack is made possible because an attacker can first deliver a malicious payload to the phone’s modem using the RCE flaw and then place a video call to the device, which the victim must answer for the exploit to work.
SSD Secure Disclosure demonstrated the attack chain in a controlled environment against a Realme C33 smartphone running the affected firmware. The researchers confirmed that the vulnerability also exists on Xiaomi Redmi A5 devices running January 2026’s Android security patch and Motorola E13 devices with February 2025’s patch. However, it is unclear whether other manufacturers’ devices are affected as well.
SSD’s findings highlight a significant and often overlooked attack surface in cellular modems, which are increasingly being targeted by attackers due to their widespread use and remote accessibility. As researchers at Google’s Project Zero have previously demonstrated with Samsung’s Exynos modems, these vulnerabilities can be exploited without user interaction or even just using the victim’s phone number.
The lack of response from Unisoc Technologies Co. Ltd., the company behind the affected modem firmware, is also concerning. SSD Secure Disclosure attempted to reach out to the vendor multiple times via email and LinkedIn but received no response. In light of these findings, users are advised to be cautious when answering video calls on their Android devices and ensure that their security patches are up-to-date.
The discovery serves as a reminder that even seemingly innocuous features like video calling can be used as attack vectors by malicious actors. As the number of connected devices continues to grow, it is essential for manufacturers and users alike to prioritize the security of these devices and stay vigilant against emerging threats.
Source: Dark Reading — 2026-08-17