Video Call Exploit Chains Two Flaws in Unisoc Modems
Researchers have uncovered a new flaw in Unisoc T612 modem firmware that, when chained with a previously disclosed remote code execution (RCE) vulnerability, could allow an attacker to gain privileged access to the Android kernel on affected devices.
A threat actor could trigger the attack by first delivering a malicious payload to the phone’s modem via the previous RCE vulnerability and then placing a video call to the device, which the victim would need to answer for the exploit to work.
A Two-Stage Unisoc Attack Chain
Researchers at SSD Secure Disclosure, who discovered both the new flaw in Unisoc’s T612 modem firmware and the previously disclosed RCE vulnerability, demonstrated the attack chain in a controlled setting against a Realme C33 smartphone running the affected firmware.
SSD confirmed the vulnerability on a Xiaomi Redmi A5 running the January 2026 Android security patch and a Motorola E13 running the February 2025 patch. The company did not indicate if it believed devices from other manufacturers were affected as well.
«We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response,» SSD Secure wrote in the research post.
Unisoc Technologies Co. Ltd. is a Chinese semiconductor design company that develops chipsets and platforms for mobile phones, IoT (Internet of Things) devices, automotive systems, tablets, wearables and other connected devices. Multiple mobile device manufacturers including Motorola, Samsung, Realme, Nokia, and ZTE currently use Unisoc chipsets.
The new flaw that SSD Security discovered is a memory-isolation weakness in Unisoc’s T612 modem’s memory protection unit. The firmware flaw allows an attacker who already has access to the modem to escalate privileges and gain kernel level privileges on an affected Android device. The flaw is the second in recent months that SSD Security has disclosed in the Unisoc T612 chipset.
In March, the company discovered a remote code execution vulnerability (RCE) in the T612 modem’s handling of the Session Initiation Protocol/Session Description Protocol (SIP/SDP) data used in establishing and describing voice and video calls. SSD described the flaw as enabling an attacker to use a specially crafted message to corrupt the modem’s memory and run their own code on it.
SSD’s Proof of Concept Exploit
In its proof of concept, SSD chained the RCE with the newly discovered memory isolation weakness to gain kernel access on an Android device. The researchers first exploited the RCE in the modem by sending specially crafted SIP/SDP messages that placed code and fragments of a larger payload in the modem’s memory.
SSD then showed how an attacker could make a video call to the victim’s device. If the victim answers, the exploit reassembles the fragmented payload and executes code that allows an attacker to disable the modem’s memory protections and access Android kernel memory.
For the demonstration, SSD used a Realme C33 running Android with the Unisoc T612 and the July 1, 2025, security update as the victim device. The researchers built their own test 4G/VoLTE network to conduct the demonstration, using software and hardware that simulated a cellular network. They used a separate computer to run the attack code and send the malicious SIP/SDP messages. But in an actual attack, an adversary could use any smartphone capable of making a video call to trigger the exploit on the victim’s device, SSD said.
SSD’s findings are consistent with previous reports showing cellular modems are a significant and often remotely reachable attack surface. Check Point researchers previously reported a remotely exploitable flaw in Unisoc’s baseband that could disrupt cellular communications. Researchers at Google’s Project Zero demonstrated multiple vulnerabilities in Samsung’s Exynos modems that enabled RCE with no user interaction and in some cases required only the victim’s phone number.
Nos llegó este contenido de ciberseguridad de: DarkReading
Podrás encontrar la noticia original en el enlace que se encuentra a continuación: https://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modems