A critical vulnerability in UNISOC modem firmware could allow for arbitrary code execution with kernel privileges, potentially enabling an attacker to modify the Android kernel. The flaw, identified as Common Weakness Enumeration (CWE) 1189 for Improper Isolation of Shared Resources on System-on-a-Chip (SoC), stems from a lack of isolation between modem memory and kernel memory.
The issue was discovered by independent security researcher 0x50594d and disclosed by the SSD Secure Disclosure technical team. SSD demonstrated a full exploit chain, showing how modem-level code execution could be escalated to kernel-level execution.
The researchers explained that the missing isolation allows code running within the modem context to access memory used by the Android kernel. An attacker who has already achieved code execution on the modem can then disable protections on a Memory Protection Unit (MPU) region, granting the modem context access to physical memory, including that of the Android kernel.
SSD tested the full exploit chain against a Realme C33 running an Android security update from July 2025. This test built upon a previously disclosed UNISOC T612 RCE, demonstrating the execution of a payload in kernel space. The final stage of the attack was triggered by placing a video call to the target phone using a Voice over Long-Term Evolution (VoLTE) connection in their test environment.
Affected devices include phones utilizing UNISOC chipsets. SSD specifically listed the Xiaomi Redmi A5 with a January 1, 2026 security patch and the Motorola E13 with a February 1, 2025 security patch as examples, though they noted this is not an exhaustive list.
UNISOC, a global fabless semiconductor company specializing in mobile communication, IoT, and smart device chipsets, has not yet publicly commented on the vulnerability. SSD stated they attempted to contact UNISOC via email and LinkedIn, but no response has been reported.
For owners of affected devices, firmware updates from UNISOC and handset manufacturers are the primary means of remediation. This vulnerability highlights ongoing concerns about the security of cellular modem components, following similar risks demonstrated in other modems in recent years.






