Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

ETSI Proposes 17 Cybersecurity Standards to Support EU CRA

August 17, 2026

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

August 17, 2026

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

August 17, 2026
Facebook X (Twitter) Instagram
Monday, August 17
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»UNISOC Modem Flaw Enables Remote Code Execution via Video Calls
Cyber Security

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

Team-CWDBy Team-CWDAugust 17, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A vulnerability in UNISOC modem firmware can allow arbitrary code execution with kernel privileges from the modem context, potentially allowing an attacker to modify Android kernel code.

The flaw stems from a lack of isolation between modem memory and kernel memory. This is according to new research by the SSD Secure Disclosure technical team, which was credited to independent security researcher 0x50594d. The firm demonstrated a full exploit chain in which modem-level code execution was extended into kernel-level execution.

The issue has been identified in phones using UNISOC chipsets, with SSD listing the Xiaomi Redmi A5 with a January 1, 2026 security patch and the Motorola E13 with a February 1, 2025 security patch among affected devices.

SSD classified the underlying flaw as Improper Isolation of Shared Resources on System-on-a-Chip (SoC), tracked as Common Weakness Enumeration (CWE) 1189. The researchers said the missing isolation allows code running in the modem context to access memory used by the Android kernel.

Read more on Android vulnerabilities: Large-Scale Malicious App Campaign Bypassing Android Security

Modem Isolation Failure Enables Kernel Access

The vulnerability allows an attacker who has already gained code execution on the modem to disable protections on a Memory Protection Unit (MPU) region. This gives the modem context access to physical memory, including memory used by the Android kernel.

SSD tested the full chain against a Realme C33 with an Android security update from July 2025. The disclosure links the test to a previously disclosed UNISOC T612 RCE and demonstrates the resulting execution of a payload in kernel space.

The final stage was triggered by placing a video call to the target phone. The researchers used a Voice over Long-Term Evolution (VoLTE) connection in their test environment, demonstrating how modem-level execution could be extended to kernel-level code execution.

No UNISOC Response Reported

The disclosure does not identify a vendor firmware update addressing the flaw. SSD also does not present its listed devices as an exhaustive inventory of affected phones.

For affected device owners, the disclosure leaves firmware updates from UNISOC and handset manufacturers as the key route to remediation.

Similar risks have been demonstrated in other cellular modem components, including Cinterion modem vulnerabilities in 2024 that researchers said could allow remote attackers to execute arbitrary code and manipulate device memory.

SSD said it attempted to contact UNISOC through email and LinkedIn. Infosecurity has also contacted UNISOC for comment but has not received a response at the time of writing.

UNISOC (Shanghai) Technologies  is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication, IoT and smart device chipsets.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover
Next Article BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Team-CWD
  • Website

Related Posts

Cyber Security

Privacy in an AI World Should be the Default Not a Feature

August 14, 2026
Cyber Security

RISE with SAP & SAP IDM Sunset: Two Deadlines, One Identity Strategy

August 14, 2026
Cyber Security

ICO Reprimands Criminal Records Office After 2023 Breach

August 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What it takes to fool facial recognition

March 14, 2026

Is it OK to let your children post selfies online?

February 17, 2026

The hidden risks of browser extensions – and how to avoid them

September 13, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.