Unisoc VoLTE Exploit Grants Full Android Kernel Access

Security researchers have unveiled a two-stage exploit chain targeting Unisoc modem firmware, enabling attackers to gain full Android kernel access through a VoLTE video call. This vulnerability remains unpatched by the chipset manufacturer.

The initial stage of this exploit was disclosed in March 2026, revealing a remote code execution flaw in Unisoc’s modem firmware triggered by a malformed SIP video call. To complete the exploit chain, an attacker must control a private 4G cellular network and have the victim answer a malicious video call.

Despite multiple attempts to contact Unisoc via email and LinkedIn, researchers have not received any response. Consequently, no CVE identifier has been assigned to this privilege-escalation vulnerability, classified as CWE-1189: Improper Isolation of Shared Resources on System-on-a-Chip.

The flaw affects at least three Unisoc chipsets: the T606 in the Motorola E13, the T612 in the Realme C33, and the T7250 in the Xiaomi Redmi A5. Unisoc, formerly known as Spreadtrum, supplies components to brands like Motorola, Realme, and Xiaomi, with devices sold in over 140 countries.

Researchers confirmed the vulnerability on a Motorola E13 with a February 2025 security patch and a Xiaomi Redmi A5 with a January 2026 patch. Exploiting this flaw requires an attacker to first achieve modem-level access via the March 2026 RCE vulnerability, control VoLTE infrastructure, and have the victim answer the malicious video call.

The proof-of-concept environment utilized an open-source 4G core network, a software-defined radio for the 4G interface, and specialized SIM cards. Once code execution is achieved on the modem, the attacker can manipulate the modem’s ARM Memory Protection Unit to map the entire 32-bit physical address space as readable, writable, and executable, including the Android kernel memory.

This exploit is possible due to shared physical memory between the modem and application processors within the Unisoc SoC, lacking hardware-enforced boundaries to prevent modem-context code from modifying kernel memory. Researchers confirmed kernel-level code execution by observing kernel log outputs indicating the injected payload had run.

The August 2026 Android Security Bulletin does not address this privilege-escalation vulnerability, and no Unisoc security bulletin covers it. A separate Unisoc advisory from October 2025, CVE-2025-31718, describes a modem input-validation flaw on the same chipset family, though its relation to the March 2026 disclosure is unclear.

Device owners currently have no available patch or mitigation and should monitor for firmware updates from their device manufacturers.

This disclosure follows independent research published in November 2025 by Kaspersky ICS CERT, which documented a similar architectural condition on a different Unisoc chip, the UIS7862A, found in vehicle head units. After gaining modem code execution via a separate vulnerability, the Kaspersky team was also able to reach and modify the running Android kernel by exploiting the modem’s access to shared memory.

The persistence of such vulnerabilities in Unisoc’s modem firmware underscores the critical need for robust security measures in mobile chipsets. Users should remain vigilant and promptly apply firmware updates when available to mitigate potential risks.