Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers have discovered a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call.

Security researchers have uncovered a serious vulnerability in Unisoc modem firmware that allows attackers to gain full access to the Android kernel on affected devices.
The vulnerability, discovered by SSD Secure Disclosure, is a two-stage exploit chain that requires the attacker to control a private 4G cellular network and the victim to answer an incoming video call. The first stage of the exploit chain was disclosed in March 2026, when SSD Secure Disclosure revealed a remote code execution vulnerability in the same firmware through a malformed SIP video call.
The researchers have confirmed that the privilege-escalation vulnerability resides in the modem firmware shared by at least three Unisoc chipsets, including the T606 found in the Motorola E13, the T612 found in the Realme C33, and the T7250 found in the Xiaomi Redmi A5.
| Chipset | Device Model | | --- | --- | | T606 | Motorola E13 | | T612 | Realme C33 | | T7250 | Xiaomi Redmi A5 |
Unisoc, a Shanghai-based chipmaker, supplies components to brands including Motorola, Realme, and Xiaomi for devices sold across more than 140 countries.
The researchers built their proof-of-concept environment using an open-source 4G core network, a software-defined radio for the 4G radio interface, and specialized SIM cards. Once code is running on the modem, the privilege-escalation step works by writing a full-access configuration to the modem's ARM Memory Protection Unit through coprocessor registers, mapping the entire 32-bit physical address space as readable, writable, and executable from modem context.
The condition making this possible is a shared physical memory space between the modem processor and the application processor within the Unisoc SoC, with no hardware-enforced boundary preventing modem-context code from modifying kernel memory.
Researchers confirmed kernel-level code execution on a test device by observing kernel log output showing that the injected payload had run. However, the August 2026 Android Security Bulletin does not address the privilege-escalation vulnerability, and no UNISOC security bulletin covers it.
Device owners currently have no available patch or mitigation and should watch for a firmware update from their device manufacturer.
The disclosure follows independent research published in November 2025 by Kaspersky ICS CERT, which documented the same architectural condition on a different Unisoc chip, the UIS7862A, found in vehicle head units. After gaining modem code execution via a separate vulnerability, the Kaspersky team was also able to reach and modify the running Android kernel by exploiting the modem and application processor's shared physical address space.
Kaspersky described one of its lateral movement paths, involving a hidden Direct Memory Access peripheral, as a hardware-level issue not fixable through a software update. The Memory Protection Unit route used in the SSD chain is in principle addressable through a firmware change, though no such update has been committed to by UNISOC.
A coordinated Unisoc modem vulnerability uncovered by Check Point Research in 2022, CVE-2022-20210, was patched by UNISOC and distributed through the Android Security Bulletin. The two currently disclosed vulnerabilities carry no such assurance.
The researchers have tried to reach out to the vendor through multiple channels, but have not received any response. As a result, device owners currently have no available patch or mitigation and should watch for a firmware update from their device manufacturer.





