Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Overview
Researchers from SSD Secure Disclosure have identified a serious vulnerability in Unisoc modem firmware that allows attackers to gain full access to the Android kernel through a VoLTE video call. This exploit chain, disclosed on August 17, 2026, is a continuation of a previous discovery from March 2026, which involved remote code execution. Currently, there is no fix available from Unisoc, leaving devices that use this firmware at risk. The implications of this vulnerability are significant, as it can potentially allow attackers to control affected devices completely. Users with devices running Unisoc chipsets should be particularly cautious, as they are directly impacted by this security issue.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Devices using Unisoc modem firmware
- Timeline: Ongoing since March 2026
Original Article Summary
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker. The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the
Impact
Devices using Unisoc modem firmware
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since March 2026
Remediation
Not specified
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Android, Google, Exploit, and 1 more.