UNISOC modem flaw enabled kernel-level code execution through video calls

A critical vulnerability in UNISOC modem firmware could allow for arbitrary code execution with kernel privileges, potentially enabling an attacker to modify the Android kernel. The flaw, identified as Common Weakness Enumeration (CWE) 1189 for Improper Isolation of Shared Resources on System-on-a-Chip (SoC), stems from a lack of isolation between modem memory and kernel memory.
The issue was discovered by independent security researcher 0x50594d and disclosed by the SSD Secure Disclosure technical team. SSD demonstrated a full exploit chain, showing how modem-level code execution could be escalated to kernel-level execution.
The researchers explained that the missing isolation allows code running within the modem context to access memory used by the Android kernel. An attacker who has already achieved code execution on the modem can then disable protections on a Memory Protection Unit (MPU) region, granting the modem context access to physical memory, including that of the Android kernel.
SSD tested the full exploit chain against a Realme C33 running an Android security update from July 2025. This test built upon a previously disclosed UNISOC T612 RCE, demonstrating the execution of a payload in kernel space. The final stage of the attack was triggered by placing a video call to the target phone using a Voice over Long-Term Evolution (VoLTE) connection in their test environment.
Affected devices include phones utilizing UNISOC chipsets. SSD specifically listed the Xiaomi Redmi A5 with a January 1, 2026 security patch and the Motorola E13 with a February 1, 2025 security patch as examples, though they noted this is not an exhaustive list.
UNISOC, a global fabless semiconductor company specializing in mobile communication, IoT, and smart device chipsets, has not yet publicly commented on the vulnerability. SSD stated they attempted to contact UNISOC via email and LinkedIn, but no response has been reported.
For owners of affected devices, firmware updates from UNISOC and handset manufacturers are the primary means of remediation. This vulnerability highlights ongoing concerns about the security of cellular modem components, following similar risks demonstrated in other modems in recent years.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]