On August 17, 2026, researchers disclosed a critical, unpatched two-stage exploit chain affecting Android devices that use Unisoc modem firmware. The attack, initiated via a malicious Voice over LTE (VoLTE) video call, can provide a remote attacker with full kernel-level access to the target device. The exploit chain combines a previously disclosed remote code execution (RCE) vulnerability in the modem with a new privilege escalation flaw (CWE-1189) that allows an attacker to pivot from the modem's isolated environment to the main application processor, gaining complete control over the Android operating system. The chipmaker Unisoc has allegedly been unresponsive to disclosure attempts, leaving numerous devices from vendors like Motorola, Realme, and Xiaomi vulnerable with no available patch.
The attack consists of two distinct stages:
The attack is complex, requiring the threat actor to operate their own 4G cellular network (e.g., using open-source tools like srsRAN) and for the target to accept the incoming malicious video call. Despite the complexity, the impact is maximum, granting total control over the device.
The vulnerability has been confirmed on devices with the following Unisoc chipsets:
These chipsets are commonly found in budget to mid-range smartphones sold globally. Specific devices confirmed to be vulnerable include:
Given that Unisoc chips are used in devices sold in over 140 countries, the potential scope of affected users is significant.
There is currently no evidence of this exploit chain being used in the wild. The disclosure was made by security researchers to bring attention to the unpatched issue. However, the publication of the technical details, while omitting a full PoC, provides a roadmap for advanced threat actors to develop their own exploits. The lack of a CVE identifier or an official security bulletin from Unisoc or Google indicates the vulnerability remains unaddressed.
A successful exploit gives an attacker complete and persistent control over the target Android device. This level of access, equivalent to a kernel-level rootkit, allows for:
Due to the nature of the attack (requiring a malicious base station), detection on the device itself is extremely difficult for an end-user. For telecommunications providers and researchers:
ramdump files) might reveal evidence of the initial exploitation, though this is a highly specialized forensic task.Given the lack of a patch, detection is challenging. Advanced mobile threat defense (MTD) solutions might be able to detect post-exploitation behavior, such as unexpected processes running with kernel privileges or anomalous network traffic originating from a compromised device. However, a sophisticated attacker with kernel access could likely hide their tracks from such solutions.
As of August 17, 2026, there is no patch or effective mitigation for end-users. The responsibility lies with Unisoc to fix the firmware and for device manufacturers (Motorola, Realme, Xiaomi, etc.) to distribute the update.
The only effective mitigation is a firmware update from the device manufacturer that patches the underlying Unisoc modem vulnerabilities. Users should apply this update as soon as it is available.
While not practical for most users, in high-security environments, devices could be restricted to trusted cellular networks, although this does not prevent a sophisticated attacker with the ability to spoof a trusted network.
Given the severity of the unpatched Unisoc modem exploit, the sole effective remediation is a firmware update. Owners of affected devices, including the Motorola E13, Realme C33, and Xiaomi Redmi A5, must be vigilant for over-the-air (OTA) security updates from their respective manufacturers. It is critical to enable automatic updates and manually check for new patches regularly via the device's settings menu. Until Unisoc provides a fix to the device manufacturers and they, in turn, push it to end-users, these devices remain exposed to an attack that grants full kernel control. This situation underscores the dependency on the hardware supply chain for security and leaves users with no immediate defensive action other than awaiting a patch.
The initial remote code execution vulnerability in Unisoc modem firmware was first disclosed by SSD Secure Disclosure.
Researchers publish details of the full two-stage exploit chain, including the kernel privilege escalation vulnerability.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.