Skip to content
Video Call Exploit Chains Two Flaws in Unisoc Modems

Video Call Exploit Chains Two Flaws in Unisoc Modems

Darkreading Jai Vijayan August 17, 2026

Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.

Researchers have uncovered a new flaw in Unisoc T612 modem firmware that, when chained with a previously disclosed remote code execution (RCE) vulnerability, could allow an attacker to gain privileged access to the Android kernel on affected devices.

A threat actor could trigger the attack by first delivering a malicious payload to the phone's modem via the RCE vulnerability and then placing a video call to the device, which the victim would need to answer for the exploit to work.

Researchers at SSD Secure Disclosure, who discovered both the new flaw in Unisoc's T612 modem firmware and the previously disclosed RCE vulnerability, demonstrated the attack chain in a controlled setting against a Realme C33 smartphone running the affected firmware.

SSD confirmed the vulnerability on a Xiaomi Redmi A5 running the January 2026 Android security patch and a Motorola E13 running the February 2025 patch. The company did not indicate if it believed devices from other manufacturers were affected as well.

"We have tried to reach out to the vendor through multiple channels (email and ) but have not been able to receive any response," SSD Secure wrote in the research post.

Unisoc Technologies Co. Ltd. is a Chinese semiconductor design company that develops chipsets and platforms for mobile phones, IoT (Internet of Things) devices , automotive systems, tablets, wearables and other connected devices. Multiple mobile device manufacturers including Motorola, Samsung, Realme, Nokia, and ZTE currently use Unisoc chipsets.

The new flaw that SSD Security discovered is a memory-isolation weakness in Unisoc's T612 modem's memory protection unit. The firmware flaw allows an attacker who already has access to the modem to escalate privileges and gain kernel level privileges on an affected Android device. The flaw is the second in recent months that SSD Security has disclosed in the Unisoc T612 chipset.

In March, the company discovered a remote code execution vulnerability (RCE) in the T612 modem's handling of the Session Initiation Protocol/Session Description Protocol ( SIP/SDP ) data used in establishing and describing voice and video calls. SSD described the flaw as enabling an attacker to use a specially crafted message to corrupt the modem's memory and run their own code on it.

In its proof of concept, SSD chained the RCE with the newly discovered memory isolation weakness to gain kernel access on an Android device. The researchers first exploited the RCE in the modem by sending specially crafted SIP/SDP messages that placed code and fragments of a larger payload in the modem's memory.

SSD then showed how an attacker could make a video call to the victim's device. If the victim answers, the exploit reassembles the fragmented payload and executes code that allows an attacker to disable the modem's memory protections and access Android kernel memory.

For the demonstration, SSD used a Realme C33 running Android with the Unisoc T612 and the July 1, 2025, security update as the victim device. The researchers built their own test 4G/VoLTE network to conduct the demonstration, using software and hardware that simulated a cellular network. They used a separate computer to run the attack code and send the malicious SIP/SDP messages. But in an actual attack, an adversary could use any smartphone capable of making a video call to trigger the exploit on the victim's device, SSD said.

SSD's findings are consistent with reports showing cellular modems are a significant and often remotely reachable attack surface. Check Point researchers previously reported a remotely exploitable flaw in Unisoc's baseband that could disrupt cellular communications. Researchers at Google's Project Zero demonstrated multiple vulnerabilities in Samsung's Exynos modems that enabled RCE with no user interaction and in some cases required only the victim's phone number.

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

What Every Enterprise Should Know Securing Cloud Assets In the Age of AI

The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember

Building a Secure AI Strategy for the Enterprise

Is your AppSec program Mythos Ready?

Experts Explain How to Develop a Framework for Cyber-Fraud Fusion