Security researchers at SSD Secure Disclosure have uncovered a critical two-stage exploit chain allowing full kernel access via VoLTE video calls on Unisoc-powered devices.
- Critical exploit chain discovered in Unisoc modem firmware.
- Attackers can gain full Android Kernel access via a simple VoLTE video call.
- Zero-click potential: No user interaction is required for the initial breach.
- No official fix or patch has been released by Unisoc yet.
In a startling revelation, security researchers at SSD Secure Disclosure have published details of a sophisticated two-stage exploit chain that targets devices utilizing Unisoc modem firmware. This vulnerability allows a remote attacker to bypass standard security layers and achieve the highest level of privilege: full access to the Android Kernel.
The attack vector is particularly alarming as it leverages VoLTE (Voice over LTE) video calling. Unlike traditional phishing attacks that require a user to click a malicious link or install a rogue application, this exploit can be triggered simply by initiating a video call to the target device, making it a highly potent weapon for targeted surveillance or data theft.
Why This Matters
BozokMedia analysis shows that modem-level vulnerabilities are exceptionally dangerous because the modem often operates as a separate processor with its own operating system. When an attacker escapes the modem's sandbox to reach the Android Kernel, they effectively become the 'super-user' of the device, gaining unrestricted access to encrypted messages, passwords, and real-time location tracking.
"The ability to achieve kernel-level execution via a telephony protocol represents a worst-case scenario for mobile device security."
This advisory, published on August 17, 2026, is the culmination of research that began in March 2026. The first stage involved remote code execution (RCE), and this second stage completes the chain by escalating those privileges to the kernel. Historically, such 'zero-click' exploits have been the hallmark of state-sponsored spyware, emphasizing the severity of this discovery.
Frequently Asked Questions
Q1: Which devices are affected by this vulnerability?
Any Android device using Unisoc modem firmware that has not received a specific patch for this exploit chain is potentially vulnerable.
Q2: How can users protect themselves?
Until a firmware update is released, users are advised to be cautious of video calls from unknown sources and keep their system software updated.