Security researchers have disclosed a critical Unisoc modem flaw that could let an attacker compromise certain budget Android phones through a malicious video call. The proof of concept reportedly achieved kernel-level access on test devices from Realme, Xiaomi and Motorola.
The research used a controlled VoLTE environment. It remains unclear whether the same attack would work on live carrier networks.
Flaw affects several Unisoc chipsets
The vulnerability affects modem firmware used across Unisoc T612, T616, T606 and T7250 chipsets. These components appear in many entry-level Android phones sold by major brands.
Researchers tested the exploit against a Realme C33 and confirmed that it also worked on a Xiaomi Redmi A5 and Motorola E13. The tested phones used Android security patches from January 2026 and February 2025.
The Unisoc modem flaw allows code running in the modem environment to gain extensive access to device memory. An attacker could then potentially modify Android’s kernel, the core software that controls the operating system.
Attack begins with an answered video call
According to the disclosure, an attacker would need to place a malicious video call to the target device. The exploit activates only if the recipient answers the call.
The researchers developed and tested the proof of concept using their own controlled VoLTE infrastructure and rooted devices. They did not test it against real mobile carrier networks.
That limitation matters. Network operators may block, alter or reject the unusual call-signalling traffic needed by the attack. As a result, researchers have not confirmed that criminals could reproduce the technique in real-world conditions.
Shared-memory weakness enables deeper access
The vulnerability stems from insufficient isolation between modem memory and Android kernel memory.
In simple terms, code running in the modem context may be able to access protected areas of the phone’s memory. This could allow an attacker to bypass safeguards and alter critical Android components.
The potential impact is severe because kernel access could let an attacker install persistent malware, monitor device activity or access sensitive information.
However, researchers have not reported real-world exploitation of the Unisoc modem flaw.
No patch or CVE has been announced
The researcher published the advisory and proof-of-concept code on 17 August 2026. At the time of disclosure, the issue had no CVE identifier and no patch status had been announced.
The researcher said Unisoc did not respond to repeated disclosure attempts made through email and LinkedIn.
Users cannot easily identify whether their phone contains an affected modem. Owners of budget Android devices should keep Android and carrier updates installed, avoid answering unexpected video calls where possible, and remain alert for security updates from their phone manufacturer.


0 responses to “Unisoc Modem Flaw Lets Attackers Target Android Phones Through Video Calls”