Unisoc VoLTE Video Call Exploit Chain Enables Full Android Kernel Access Without Vendor Fix
Security researchers have discovered a two-stage exploit chain in Unisoc modem firmware that grants full Android kernel access via VoLTE video calls, with no vendor response or patch available. The vulnerability stems from improper isolation of shared resources in multiple Unisoc chipsets, affecting devices like Motorola, Realme, and Xiaomi models.
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker.
The advisory, published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the
*** END OF TRANSMISSION ***