PULSE the living trend engine
▲ Peaking Technology

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

A critical exploit chain in Unisoc modems allows attackers to gain full Android kernel access via a single VoLTE video call, impacting millions of devices.

5sources
5articles
3velocity
+0%since first seen
3h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

A critical security vulnerability has been identified in Unisoc modems that allows remote attackers to gain full access to the Android kernel. According to reports from The Hacker News and Cybernews, this vulnerability is triggered through a VoLTE video call, which can lead to the rooting of millions of Unisoc-powered Android phones. The attack mechanism is described as an exploit chain that enables remote code execution, potentially giving an attacker complete control over the affected mobile device after a single video call is initiated. Multiple cybersecurity outlets are tracking the development of this flaw. Infosecurity Magazine highlights that the modem flaw specifically enables remote code execution via video calls, while Dark Reading specifies that the exploit chain consists of two distinct flaws within the Unisoc modems.

Coverage from Startup Fortune emphasizes the scale of the risk, noting that the ability to root devices through this method puts millions of users at risk of unauthorized system-level access. These outlets collectively describe the flaw as a critical threat to the Android ecosystem. To understand the significance of this event, it is necessary to note that the exploit targets the VoLTE (Voice over Long-Term Evolution) functionality within Unisoc hardware. Because this attack occurs at the modem level and can escalate to full kernel access, it bypasses many standard Android security layers. The ability to achieve remote code execution without requiring user interaction beyond receiving a call makes this a high-severity issue for any device utilizing a Unisoc chipset, as it provides a direct path to the most privileged part of the operating system.

Future developments will likely focus on the deployment of patches to address the two flaws identified in the exploit chain. Since coverage from Cybernews and The Hacker News establishes that millions of phones are currently exposed, the priority will be the release of firmware updates from device manufacturers using Unisoc components. Observers will be monitoring whether these updates can effectively close the vulnerability in the modem's handling of VoLTE video calls to prevent unauthorized kernel access and device rooting.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.

Quick answers

How is the Unisoc exploit triggered?

The exploit is triggered via a VoLTE video call.

What is the maximum level of access an attacker can gain?

Attackers can gain full Android kernel access and root the device.

How many flaws are involved in the exploit chain?

According to Dark Reading, the exploit chains two flaws in Unisoc modems.

Coverage (5)

Topics

Related trends

↓ Cooling Technology 🔮 fades

iOS 27 Finally Fixes Replying to Android Texts

Apple has released iOS 27, which resolves a long-standing limitation regarding inline text replies when messaging Android users.

4 sources 5 articles v 3 11h ago