logo

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

ID: a2f42e4e-2b2b-50ad-ba4f-c4b7a1abbcaa

STIX ID: report--a2f42e4e-2b2b-50ad-ba4f-c4b7a1abbcaa

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-08-17

Date Updated: 2026-08-17

...
...

A UNISOC modem firmware vulnerability allows modem-level code to disable Memory Protection Unit (MPU) protections and access physical memory used by the Android kernel, enabling escalation to kernel-level arbitrary code execution. SSD Secure Disclosure (credited to researcher 0x50594d) demonstrated a full exploit chain—including a VoLTE-triggered final stage—tested on a Realme C33 and listed affected devices (e.g., Xiaomi Redmi A5, Motorola E13); no UNISOC firmware update has been reported, leaving vendor and handset firmware updates as the primary remediation path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.