UNISOC modem flaws allow attackers to gain Android kernel access 

Researchers at SSD Secure Disclosure have demonstrated an exploit chain in UNISOC modem firmware that can give an attacker full Android kernel access after a target answers a malicious VoLTE video call.

The attack combines a previously disclosed remote code execution vulnerability with a newly identified privilege-escalation flaw caused by inadequate isolation between the modem and application processor.

The vulnerabilities affect firmware used across UNISOC T606, T612, T616 and T7250 chipsets, found in devices including the Realme C33, Motorola E13 and Xiaomi Redmi A5. Researchers demonstrated the attack using their own 4G/VoLTE infrastructure and said UNISOC has not responded to their disclosure attempts.

At the time of publication, the newly disclosed privilege-escalation flaw had no CVE, patch or published mitigation.

Seemant Sehgal, Founder & CEO, BreachLock:

   “Answering a phone call shouldn’t have to be a security decision, but that is exactly what this vulnerability forces on users. The modem and the application processor were designed to stay in their lanes, and when that boundary fails, an attacker inherits the same trust the hardware assumed was protected. What makes this harder to dismiss is the chipset reach. These are not boutique devices; they are everyday consumer hardware at price points that serve populations who have no realistic path to a patch.

   “Firmware-level vulnerabilities of this kind sit below the visibility of most mobile security tools. Oftentimes, users can’t detect what they can’t see, and right now there is no patch and no CVE. The burden falls almost entirely on the device manufacturer to move quickly, and on users to stay informed about whether their specific device receives an update.”

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:

   “SSD Secure Disclosure’s exploit reconfigures the modem’s Memory Protection Unit (MPU), the hardware barrier between the modem and the rest of the device, in seven lines of code. Once that barrier is down, the modem gains unrestricted access to the Android kernel, the core of the operating system that controls everything on the phone. An attacker at that level could intercept communications and exfiltrate data while operating beneath normal Android security applications, all triggered when the target answers a video call.

   “Android’s security model assumes the modem is isolated from the processor that runs the operating system and apps. UNISOC’s implementation allows code executing in the modem context to disable the MPU protections separating those domains, so a modem vulnerability can become a compromise of the Android kernel itself. SSD tested the full chain on a device running a July 2025 Android security update, which means Google’s ordinary Android security patches alone can’t fix an isolation failure in UNISOC’s modem layer.

   “Two independent research teams have now demonstrated modem-to-kernel compromise on different UNISOC chips within nine months. Kaspersky researchers showed a similar escalation path on the UIS7862A, used in vehicle head units, in November 2025, pivoting from modem code execution into the Android kernel through weaknesses in the System-on-Chip’s (SoC’s) isolation architecture. SSD’s chain targets the T612 in smartphones.

   “Different exploitation mechanisms, but the same underlying failure pattern across different chips and product categories, modem compromise can cross a boundary that is supposed to protect the application processor. That pattern points to a design decision in UNISOC’s silicon, not a one-off firmware bug.

   “UNISOC holds 14% of the global smartphone chipset market, up from 10% a year ago, powering devices from Xiaomi, Motorola, and Realme across 140 countries. The flaw carries no Common Vulnerabilities and Exposures (CVE) number, no patch, and no vendor acknowledgment. Remediation depends entirely on UNISOC shipping firmware updates and device manufacturers distributing them, a pipeline that barely functions for budget phones under normal circumstances.”

Donald McFarlane, Advisory Board Member, Xcape, Inc.:

   “This is not simply a vulnerability in a cellular modem. The researchers demonstrate a chain from remote code execution in the modem to compromise of the device’s kernel, showing that the isolation between the baseband and the application processor can itself become part of the attack path.

   “UNISOC is not an obscure platform. It accounts for roughly one in seven smartphone processors shipped globally, concentrated heavily in lower-cost Android devices, although we do not yet have a reliable figure for how many devices are running the specific affected modems or firmware.

   “Baseband attacks have long been among the more valuable and technically difficult areas of offensive research. What is changing is the cost of doing that research: software-defined radios, open cellular infrastructure, increasingly capable emulation and fuzzing tools, and now AI-assisted analysis of enormous protocol specifications and firmware are steadily lowering barriers that once favored very well-funded government or commercial offensive teams.

   “There is still an important distinction between finding a vulnerability and producing a reliable operational capability. A dependable zero-click chain against a modern phone can be worth millions of dollars and remains highly specialized work. Still, the underlying research is becoming substantially more accessible, especially for moderately well-funded teams such as at universities.

   “One caveat is important: this exploit was demonstrated using the researchers’ own cellular and IMS infrastructure. That establishes the vulnerability, but it does not yet prove that the same malicious signaling will reliably traverse every commercial carrier network. That is an important question for follow-on research.”

If you rely on Android devices in your enterprise, this is worth a read so that you know where your next problem may come from.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading