The Unisoc VoLTE exploit , disclosed on August 17, 2026 by researchers at SSD Secure Disclosure, is one of the most troubling exploit chains to come to light in recent years. It is a two-stage exploit chain that allows an attacker to gain full access to the Android kernel of devices using Unisoc modem firmware , through a simple incoming VoLTE video call . The most troubling aspect? The chipset manufacturer has not released any fixes.

This disclosure is the second in a chain that began in March 2026 , when SSD Secure Disclosure revealed remote code execution (RCE) in the same firmware via a forged SIP video call . The investigation was conducted by an independent security researcher with the alias 0x50594d . The team said it attempted to contact the manufacturer through multiple channels — email and LinkedIn — but received no response, just as it had with the March disclosure.
The privilege escalation is classified as CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip) and has not yet been assigned a CVE number. The flaw is located in the modem firmware shared by at least three Unisoc: the T606 found in the Motorola E13, the T612 in the Realme C33 , and the T7250 in the Xiaomi Redmi A5.
See also: Zimbra zero-click exploit: Russian group steals emails and 2FA codes via CVE-2025-66376
How the Unisoc VoLTE exploit works — Technical analysis
To understand the severity of the Unisoc VoLTE exploit , we need to examine the architectural weakness that makes it possible. In Unisoc 's SoCs (System-on-a-Chip) , the modem processor and the application processor share the same physical memory space, with no hardware-enforced boundary preventing modem-context code from modifying kernel memory. This architectural choice is at the root of the problem.
The exploit operates in two distinct stages. In Stage 1 , the attacker exploits an RCE vulnerability in the modem firmware via a forged SIP video call , achieving code execution at the modem level. In Stage 2 , the code running on the modem writes a full-access configuration to the modem's ARM Memory Protection Unit (MPU) via coprocessor registers, mapping the entire 32-bit physical address space as readable, writable, and executable from the modem context — including the pages where the Android kernel resides .
The researchers confirmed kernel-level code execution on a test device by observing the kernel log output, which showed that the injected payload had been executed. To build the proof-of-concept environment, they used an open-source 4G core network, a software-defined radio for the 4G radio interface, and specialized SIM cards. The attack was confirmed on a Motorola E13 with the February 2025 security patch and a Xiaomi Redmi A5 with the January 2026 patch.
Unisoc VoLTE exploit: Attack conditions and scope of influence
The Unisoc VoLTE exploit is not an attack that can be executed en masse. It requires two critical conditions: the attacker must control a private 4G/VoLTE infrastructure , and the victim must answer the incoming video call. This significantly limits mass exploitation, but does not reduce the risk of targeted high-value attacks — journalists, activists, business executives, or government officials.
See also: GitLab RCE PoC: Exploit in self-managed GitLab via Jupyter notebook diff (Oj)
Unisoc , a Shanghai -based chipset company formerly known as Spreadtrum , supplies components to brands such as Motorola , Realme and Xiaomi for devices sold in more than 140 countries . This means the number of potentially affected devices is huge, although no public estimate of the exact number of users has been given. The T606 , T612 and T7250 chipsets are mainly used in budget entry-level smartphones, which often receive security updates late.
It is worth noting that in August 2026, other Unisoc across multiple product lines, including improper input validation issues that can cause remote denial of service in modem firmware families such as T8100, T9100, T8200, T8300 , and UDX710. These were documented as CVE-2026-21548 through CVE-2026-21555, with multiple entries describing remote denial of service and at least one listing Android 13/14/15/16 in certain Unisoc modem families.

Security recommendations for users of Unisoc VoLTE devices
Given the lack of a patch, users of Unisoc chipset-based devices — particularly the Motorola E13 , Realme C33 , and Xiaomi Redmi A5 — should take immediate action. First, actively monitor firmware updates from their device manufacturer and install them as soon as they become available. Second, treat VoLTE video calls from unknown numbers with extreme caution, as they are the main attack vector.
See also: Gemini on Android: The test that highlighted Grok 4.5
For organizations managing fleets of devices, it is recommended to document the affected smartphone models and coordinate with OEMs on firmware release status, rather than relying solely on Android OS. If a device is critical and unpatched, consider isolating it from sensitive functionality until a fix is confirmed by the manufacturer. Also, avoiding connecting to unknown or untrusted networks reduces exposure, as the exploit chain requires 4G infrastructure under the attacker’s control.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The Unisoc highlights a broader problem in the Android: baseband modem security remains one of the most underrated attack surfaces. Once an attacker gains access to the modem, 's traditional defenses Android — sandboxing, app-layer defenses — become essentially worthless.
