On August 17, 2026, researchers disclosed a critical, unpatched two-stage exploit chain affecting Android devices that use Unisoc modem firmware. The attack, initiated via a malicious Voice over LTE (VoLTE) video call, can provide a remote attacker with full kernel-level access to the target device. The exploit chain combines a previously disclosed remote code execution (RCE) vulnerability in the modem with a new privilege escalation flaw (CWE-1189) that allows an attacker to pivot from the modem's isolated environment to the main application processor, gaining complete control over the Android operating system. The chipmaker Unisoc has allegedly been unresponsive to disclosure attempts, leaving numerous devices from vendors like Motorola, Realme, and Xiaomi vulnerable with no available patch.
The attack consists of two distinct stages:
The attack is complex, requiring the threat actor to operate their own 4G cellular network (e.g., using open-source tools like srsRAN) and for the target to accept the incoming malicious video call. Despite the complexity, the impact is maximum, granting total control over the device.
The vulnerability has been confirmed on devices with the following Unisoc chipsets:
These chipsets are commonly found in budget to mid-range smartphones sold globally. Specific devices confirmed to be vulnerable include:
Given that Unisoc chips are used in devices sold in over 140 countries, the potential scope of affected users is significant.
There is currently no evidence of this exploit chain being used in the wild. The disclosure was made by security researchers to bring attention to the unpatched issue. However, the publication of the technical details, while omitting a full PoC, provides a roadmap for advanced threat actors to develop their own exploits. The lack of a CVE identifier or an official security bulletin from Unisoc or Google indicates the vulnerability remains unaddressed.
A successful exploit gives an attacker complete and persistent control over the target Android device. This level of access, equivalent to a kernel-level rootkit, allows for:
Due to the nature of the attack (requiring a malicious base station), detection on the device itself is extremely difficult for an end-user. For telecommunications providers and researchers:
ramdump files) might reveal evidence of the initial exploitation, though this is a highly specialized forensic task.Given the lack of a patch, detection is challenging. Advanced mobile threat defense (MTD) solutions might be able to detect post-exploitation behavior, such as unexpected processes running with kernel privileges or anomalous network traffic originating from a compromised device. However, a sophisticated attacker with kernel access could likely hide their tracks from such solutions.
As of August 17, 2026, there is no patch or effective mitigation for end-users. The responsibility lies with Unisoc to fix the firmware and for device manufacturers (Motorola, Realme, Xiaomi, etc.) to distribute the update.
Android's September 2026 security update includes patches for Unisoc components, likely addressing the previously unpatched modem exploit that granted kernel access.
The September 2026 Android security update, released on September 10, 2026, includes fixes for vulnerabilities in third-party components, specifically mentioning Unisoc. This update likely addresses the critical, previously unpatched two-stage exploit chain affecting Android devices with Unisoc modem firmware, which allowed remote attackers to gain full kernel access via a malicious VoLTE video call. Users are urged to install the 2026-09-05 patch level to mitigate this and 179 other vulnerabilities. The availability of these patches significantly changes the remediation status from "no patch" to "patch available".
The initial remote code execution vulnerability in Unisoc modem firmware was first disclosed by SSD Secure Disclosure.
Researchers publish details of the full two-stage exploit chain, including the kernel privilege escalation vulnerability.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.