Desk live·
ForensicPost
Cloud/Vulnerabilities/File 26-0817

Unisoc Modem Flaw Gives Android Kernel Access Through a Video Call, With No Fix

Researchers published the second stage of a chain that turns a VoLTE video call into full Android kernel access on three Unisoc chipsets. The modem and application processor share memory with no hardware boundary, and the vendor has not answered.

Constructed geometry · not a chart of case data
JurisdictionNot establishedthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUnisoc-based Android devices
ActorUnattributed
D. Kennedy10 min readConfidence: high3 sources reviewed

SSD Secure Disclosure published the second stage of an exploit chain against Unisoc modem firmware on 17 August 2026, completing work it began in March, when the same group disclosed remote code execution in that firmware through a malformed SIP video call. The second stage lets code with a VoLTE foothold modify Android kernel memory on the T606, T612 and T7250 chipsets.

The condition that makes it work is a shared physical memory space between the modem processor and the application processor inside the system-on-chip, with no hardware-enforced boundary stopping modem-context code from reaching kernel memory. Completing the chain requires an attacker-controlled private 4G network and a victim who answers the call. The research is credited to an independent researcher using the handle 0x50594d. SSD says it tried to reach the vendor by email and LinkedIn and got no reply.

The Flaw Is The Layout

Two processors sharing memory without a boundary is not a bug in the usual sense. It is how the part was designed, and no firmware update changes it.

Forescout catalogued 56 industrial device vulnerabilities under the same heading in 2022 — insecure by design rather than mistaken. The property they share is that the fix is a different product, and the installed base cannot be given one.

Nobody Answered The Email

The researchers say they contacted the vendor through several channels and received no response. That is the part of this file with no equivalent elsewhere in the database.

We have recorded vendors doing this well and badly — Slack shipped a fix the day it was told, Sophos published five years of intrusions into its own products, Barracuda told customers to replace the hardware. All of that assumes a counterparty. Without one, coordinated disclosure has no mechanism left, and researchers choose between staying quiet and publishing to people who cannot act.

The Preconditions Are Real

This is not a drive-by. An attacker needs a private 4G network within range and the target has to answer a video call. That is a targeted capability, not a mass one, and it is worth saying before the headline travels without it.

It is also affordable for anyone who wants it. The affected chipsets ship in budget handsets, so the exposed population skews toward people who bought the cheapest phone available — the group least able to replace a device and least likely to hear that they should.

How we reported this

Compiled from SSD Secure Disclosure’s published advisories and public reporting, listed below. No CVE identifier was published in the material we reviewed and no fix is available. We have not reproduced any of the research. Corrections: corrections@forensicpost.com.

Sources
  1. Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel AccessThe Hacker News
  2. UNISOC Modem Flaw Enables Remote Code Execution via Video CallsInfosecurity Magazine
  3. UNISOC T612 LPESSD Secure Disclosure
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary