Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers have released a public proof-of-concept for a two-stage attack chain targeting Unisoc modem firmware that achieves full Android kernel access. By combining a previously disclosed remote code execution flaw in SIP video handling with a new privilege-escalation bug classified as CWE-1189, attackers can bypass hardware boundaries to map and modify kernel memory.
The vulnerability affects devices utilizing the Unisoc T606, T612, and T7250 chipsets, including the Motorola E13, Realme C33, and Xiaomi Redmi A5. Exploiting the chain requires an attacker-controlled private 4G network and victim interaction, specifically answering a malicious video call. As of the August 2026 disclosure, no CVE ID has been assigned, and neither UNISOC nor the device manufacturers have issued patches or confirmed mitigation plans.