Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
A critical exploit chain in Unisoc modems allows attackers to gain full Android kernel access via a single VoLTE video call, impacting millions of devices.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
A critical security vulnerability has been identified in Unisoc modems that allows remote attackers to gain full access to the Android kernel. According to reports from The Hacker News and Cybernews, this vulnerability is triggered through a VoLTE video call, which can lead to the rooting of millions of Unisoc-powered Android phones. The attack mechanism is described as an exploit chain that enables remote code execution, potentially giving an attacker complete control over the affected mobile device after a single video call is initiated. Multiple cybersecurity outlets are tracking the development of this flaw. Infosecurity Magazine highlights that the modem flaw specifically enables remote code execution via video calls, while Dark Reading specifies that the exploit chain consists of two distinct flaws within the Unisoc modems.
Coverage from Startup Fortune emphasizes the scale of the risk, noting that the ability to root devices through this method puts millions of users at risk of unauthorized system-level access. These outlets collectively describe the flaw as a critical threat to the Android ecosystem. To understand the significance of this event, it is necessary to note that the exploit targets the VoLTE (Voice over Long-Term Evolution) functionality within Unisoc hardware. Because this attack occurs at the modem level and can escalate to full kernel access, it bypasses many standard Android security layers. The ability to achieve remote code execution without requiring user interaction beyond receiving a call makes this a high-severity issue for any device utilizing a Unisoc chipset, as it provides a direct path to the most privileged part of the operating system.
Future developments will likely focus on the deployment of patches to address the two flaws identified in the exploit chain. Since coverage from Cybernews and The Hacker News establishes that millions of phones are currently exposed, the priority will be the release of firmware updates from device manufacturers using Unisoc components. Observers will be monitoring whether these updates can effectively close the vulnerability in the modem's handling of VoLTE video calls to prevent unauthorized kernel access and device rooting.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 2h ago.
Quick answers
How is the Unisoc exploit triggered?
The exploit is triggered via a VoLTE video call.
What is the maximum level of access an attacker can gain?
Attackers can gain full Android kernel access and root the device.
How many flaws are involved in the exploit chain?
According to Dark Reading, the exploit chains two flaws in Unisoc modems.
Coverage (5)
- A Single Video Call Can Root Millions of Unisoc-Powered Android Phones Startup Fortune · 18h ago
- UNISOC Modem Flaw Enables Remote Code Execution via Video Calls Infosecurity Magazine · 18h ago
- Video Call Exploit Chains Two Flaws in Unisoc Modems Dark Reading · 18h ago
- Millions of Android phones exposed to critical Unisoc modem flaw: full control after video call Cybernews · 18h ago
- Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access The Hacker News · 18h ago
Topics
Related trends
Massive One UI 9.5 leak reveals smoother animations, new fingerprint design, and more
A significant leak regarding Samsung's upcoming One UI 9.5 update suggests major improvements to system animations and biometric interfaces.
I've spent more than three weeks using the Galaxy Z Flip 8
Tech reviewers and users are evaluating the Samsung Galaxy Z Flip 8, focusing on its speed, regional differences, and pocket-friendly foldable design.
iOS 27 Finally Fixes Replying to Android Texts
Apple has released iOS 27, which resolves a long-standing limitation regarding inline text replies when messaging Android users.
App Lock Is Finally Coming to Android: Pixel Up First, Samsung May Be Next
Android is introducing a native App Lock feature, with Google Pixel devices expected to lead the rollout followed potentially by Samsung Galaxy phones.
Samsung is reportedly building an even wider Galaxy Z Fold 9 for video viewing
Samsung is reportedly developing a wider version of the Galaxy Z Fold 9 specifically optimized for video viewing experiences.
Google quietly resurrects a Pixel gesture we first spotted over a year ago
Google is reportedly bringing the Double-Tap-to-Lock gesture to Pixel smartphones, a feature previously seen on Samsung devices.