Security researchers at SSD Secure Disclosure have disclosed a two stage exploit chain that can achieve full Android kernel access on devices powered by Unisoc modem firmware through a Voice over LTE video call. According to the advisory published on August 17, 2026, the attack chain builds on earlier research released in March 2026 that identified a remote code execution vulnerability in the same modem firmware triggered through a malformed SIP video call. Researchers stated that successfully completing the attack requires the threat actor to control a private 4G cellular network while the targeted user must answer the incoming VoLTE video call. SSD Secure Disclosure also noted that despite multiple attempts to contact Unisoc through email and LinkedIn, the chipset manufacturer has not responded, and no security fix has been released. The research was conducted by an independent security researcher using the handle 0x50594d.
The newly disclosed privilege escalation flaw is categorized as CWE 1189, Improper Isolation of Shared Resources on System on a Chip, and has not been assigned a CVE identifier. According to the advisory, the vulnerability affects modem firmware shared across multiple Unisoc chipsets, including the T606 used in the Motorola E13, the T612 found in the Realme C33 and the T7250 powering the Xiaomi Redmi A5. Researchers confirmed successful exploitation on a Motorola E13 running the February 2025 Android security patch and on a Xiaomi Redmi A5 with the January 2026 security patch. They explained that exploitation depends on first obtaining modem level code execution using the previously disclosed March 2026 remote code execution vulnerability. Their proof of concept environment included an open source 4G core network, software defined radio hardware and specialized SIM cards that enabled the researchers to simulate the required attack conditions. Once code execution is achieved on the modem, the second stage modifies the modem ARM Memory Protection Unit configuration to map the complete 32 bit physical address space with read, write and execute permissions, allowing direct access to memory regions containing the Android kernel.
Researchers attributed the vulnerability to the shared physical memory architecture between the modem processor and the application processor inside the affected Unisoc system on chip designs. According to SSD Secure Disclosure, the lack of a hardware enforced isolation boundary allows malicious modem code to modify kernel memory directly after changing Memory Protection Unit settings. The researchers verified successful kernel level code execution by observing injected payloads being executed within the Android kernel during testing. They also noted that the August 2026 Android Security Bulletin does not include a fix for the vulnerability and that Unisoc has not issued a corresponding security advisory. Although Unisoc previously released a security advisory for CVE 2025 31718 involving another modem input validation issue within the same chipset family, researchers said it remains unclear whether that issue is related to the remote code execution vulnerability disclosed earlier this year. As a result, device owners currently have no available mitigation other than waiting for firmware updates from their device manufacturers.
The disclosure also draws attention to similar architectural concerns identified by Kaspersky ICS CERT in November 2025 while researching the Unisoc UIS7862A chipset used in vehicle head units. Kaspersky researchers demonstrated that after achieving modem code execution through a different vulnerability, they were also able to reach and modify the Android kernel because of the shared physical memory architecture between modem and application processors. Kaspersky further noted that one of its attack paths relied on a hidden Direct Memory Access component considered a hardware level issue that could not be resolved through software updates. In contrast, SSD Secure Disclosure stated that the Memory Protection Unit method identified in its research could theoretically be addressed through firmware modifications, although Unisoc has not committed to releasing an update.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





