Unpatched Unisoc Exploit Chain Gives Full Android Kernel Access

Unpatched Unisoc Modem Exploit Gives Full Android Kernel Access

CRITICAL
August 17, 2026
5m read
VulnerabilityMobile SecurityThreat Intelligence

Related Entities

Organizations

Unisoc Motorola Realme Xiaomi SSD Secure Disclosure

Products & Tech

Android VoLTESIP

Full Report

Executive Summary

On August 17, 2026, researchers disclosed a critical, unpatched two-stage exploit chain affecting Android devices that use Unisoc modem firmware. The attack, initiated via a malicious Voice over LTE (VoLTE) video call, can provide a remote attacker with full kernel-level access to the target device. The exploit chain combines a previously disclosed remote code execution (RCE) vulnerability in the modem with a new privilege escalation flaw (CWE-1189) that allows an attacker to pivot from the modem's isolated environment to the main application processor, gaining complete control over the Android operating system. The chipmaker Unisoc has allegedly been unresponsive to disclosure attempts, leaving numerous devices from vendors like Motorola, Realme, and Xiaomi vulnerable with no available patch.

Vulnerability Details

The attack consists of two distinct stages:

  1. Modem RCE: The initial entry point is a remote code execution vulnerability in the Unisoc modem firmware, first detailed in March 2026. An attacker can trigger this by sending a specially crafted Session Initiation Protocol (SIP) video call over a VoLTE network. This gives the attacker code execution within the modem's processor.
  2. Kernel Privilege Escalation: The second stage, newly disclosed, is a privilege escalation vulnerability classified as CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip). Once an attacker has control of the modem, they can exploit this flaw to break out of the modem's isolated environment and write to the physical memory accessible by the main Android kernel. This allows them to execute code with kernel-level privileges, effectively compromising the entire device.

The attack is complex, requiring the threat actor to operate their own 4G cellular network (e.g., using open-source tools like srsRAN) and for the target to accept the incoming malicious video call. Despite the complexity, the impact is maximum, granting total control over the device.

Affected Systems

The vulnerability has been confirmed on devices with the following Unisoc chipsets:

  • Unisoc T606
  • Unisoc T612
  • Unisoc T7250

These chipsets are commonly found in budget to mid-range smartphones sold globally. Specific devices confirmed to be vulnerable include:

Given that Unisoc chips are used in devices sold in over 140 countries, the potential scope of affected users is significant.

Exploitation Status

There is currently no evidence of this exploit chain being used in the wild. The disclosure was made by security researchers to bring attention to the unpatched issue. However, the publication of the technical details, while omitting a full PoC, provides a roadmap for advanced threat actors to develop their own exploits. The lack of a CVE identifier or an official security bulletin from Unisoc or Google indicates the vulnerability remains unaddressed.

Impact Assessment

A successful exploit gives an attacker complete and persistent control over the target Android device. This level of access, equivalent to a kernel-level rootkit, allows for:

  • Total Data Theft: Access to all user data, including emails, messages, photos, and application data.
  • Spyware Functionality: The ability to surreptitiously record audio, video, and GPS location, as well as log keystrokes.
  • Bypassing Security: Disabling all Android security mechanisms and sandboxing.
  • Persistence: The exploit could be used to install a persistent backdoor that survives reboots.
  • Financial Theft: Stealing credentials for banking and cryptocurrency applications.

Cyber Observables — Hunting Hints

Due to the nature of the attack (requiring a malicious base station), detection on the device itself is extremely difficult for an end-user. For telecommunications providers and researchers:

  • SIP Traffic Analysis: Monitor for malformed SIP INVITE packets related to VoLTE video calls. These packets would contain anomalies designed to trigger the initial modem RCE.
  • IMSI Catcher Detection: The attack requires a rogue cell tower. Network-level detection systems can sometimes identify IMSI catchers or rogue base stations by analyzing signal strength, cell identifiers, and network behavior.
  • Modem Crash Dumps: On a compromised device, analyzing modem crash logs (ramdump files) might reveal evidence of the initial exploitation, though this is a highly specialized forensic task.

Detection Methods

Given the lack of a patch, detection is challenging. Advanced mobile threat defense (MTD) solutions might be able to detect post-exploitation behavior, such as unexpected processes running with kernel privileges or anomalous network traffic originating from a compromised device. However, a sophisticated attacker with kernel access could likely hide their tracks from such solutions.

Remediation Steps

As of August 17, 2026, there is no patch or effective mitigation for end-users. The responsibility lies with Unisoc to fix the firmware and for device manufacturers (Motorola, Realme, Xiaomi, etc.) to distribute the update.

  • Await Patches: Users of affected devices must monitor for security updates from their manufacturers and apply them as soon as they become available.
  • VoLTE Deactivation (Theoretical): In theory, disabling VoLTE might mitigate the attack vector, but this is often not a user-configurable option and would degrade call quality by forcing calls over 2G/3G networks. It is not a practical recommendation for most users.
  • Call Screening: Be cautious of answering video calls from unknown or unexpected numbers, although a determined attacker could spoof a known contact.

Timeline of Events

1
March 1, 2026
The initial remote code execution vulnerability in Unisoc modem firmware was first disclosed by SSD Secure Disclosure.
2
August 17, 2026
Researchers publish details of the full two-stage exploit chain, including the kernel privilege escalation vulnerability.
3
August 17, 2026
This article was published

MITRE ATT&CK Mitigations

The only effective mitigation is a firmware update from the device manufacturer that patches the underlying Unisoc modem vulnerabilities. Users should apply this update as soon as it is available.

While not practical for most users, in high-security environments, devices could be restricted to trusted cellular networks, although this does not prevent a sophisticated attacker with the ability to spoof a trusted network.

D3FEND Defensive Countermeasures

Given the severity of the unpatched Unisoc modem exploit, the sole effective remediation is a firmware update. Owners of affected devices, including the Motorola E13, Realme C33, and Xiaomi Redmi A5, must be vigilant for over-the-air (OTA) security updates from their respective manufacturers. It is critical to enable automatic updates and manually check for new patches regularly via the device's settings menu. Until Unisoc provides a fix to the device manufacturers and they, in turn, push it to end-users, these devices remain exposed to an attack that grants full kernel control. This situation underscores the dependency on the hardware supply chain for security and leaves users with no immediate defensive action other than awaiting a patch.

Timeline of Events

1
March 1, 2026

The initial remote code execution vulnerability in Unisoc modem firmware was first disclosed by SSD Secure Disclosure.

2
August 17, 2026

Researchers publish details of the full two-stage exploit chain, including the kernel privilege escalation vulnerability.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

UnisocAndroidVulnerabilityZero-DayMobile SecurityVoLTEMotorolaXiaomiRealme

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.