All incidents

Unisoc modem vulnerability enables Android hijack via video call

malwareopenAug 17, 2026 — Aug 17, 2026
Unisoc modem flaw enables Android hijack via video call

RESEARCHERS have revealed that a flaw in the Unisoc T612 modem can be chained with a second vulnerability to hijack Android devices during a video call, as reported by Dark Reading. The attack was demonstrated on a Realme C33 but could affect other phones that use the same modem, including the Xiaomi Redmi A5 and Motorola E13. Successful exploitation grants the attacker kernel‑level privileges, effectively giving full control of the handset.

The exploit relies on two distinct weaknesses in the modem firmware. First, a remote code execution bug lets an attacker inject malicious code into the modem’s processor. Second, when the victim answers a video call, a second flaw triggers that escalates the modem’s access to the Android kernel, a problem catalogued as CWE‑1189 due to improper isolation between modem and kernel memory. Chaining these issues allows the modem to overwrite kernel protections and execute arbitrary code with high privileges.

SSD Secure Disclosure, which first published the findings at ssd-disclosure.com, showed that the attack disables the Memory Protection Unit, leaving kernel memory readable and writable by the modem. No CVE identifier has been assigned yet, but the researchers noted that the same modem appears in a range of budget Android models, widening the potential impact. The proof‑of‑concept relied on a specially crafted video call payload delivered over the cellular network.

To date, no threat actor has been linked to active exploitation of this flaw in the wild, and the researchers have not observed widespread abuse. However, the discovery adds to a growing list of baseband vulnerabilities that can be reached without user interaction beyond accepting a call. The situation highlights the continued risk posed by insufficient separation between cellular subsystems and the main operating system on many mobile devices.

Defenders should treat any unexpected baseband activity as a potential indicator of compromise and consider deploying mobile threat defence tools that monitor modem‑to‑kernel interactions. Users are advised to avoid answering video calls from unknown numbers and to keep their devices updated with the latest patches from the device manufacturer. Network operators can also help by filtering anomalous signalling that might carry malicious payloads aimed at the modem.

Until Unisoc releases firmware fixes, organizations can mitigate risk by disabling video call features over untrusted connections and by enforcing strict application whitelists that prevent unverified diallers from accessing the modem. Security teams should log modem‑related system calls and review them for signs of privilege escalation attempts. Staying informed about vendor advisories and applying patches promptly remains the most effective way to close this attack vector.

Intelligence briefing updated Aug 17, 2026

Root sourcessd-disclosure.com
Timeline Coverage

Swipe to explore timeline