logo

Video Call Exploit Chains Two Flaws in Unisoc Modems

ID: 55a43bde-ac3c-5ffb-abc0-f4c599a1924c

STIX ID: report--55a43bde-ac3c-5ffb-abc0-f4c599a1924c

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-08-17

Date Updated: 2026-08-18

Author: Jai Vijayan

...
...

Researchers at SSD Secure Disclosure found a memory-isolation flaw in Unisoc's T612 modem firmware which, when chained with an earlier RCE in the modem's SIP/SDP handling, enables escalation to Android kernel privileges. They demonstrated a proof-of-concept on a Realme C33 by placing payload fragments in modem memory via crafted SIP/SDP messages and then triggering reassembly and execution when the victim answers a video call; affected devices from multiple vendors using the T612 may be at risk, though SSD only confirmed tests on specific models and reported no vendor response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.