LIVE · cybersecurity feed
Live wire
vulnerability

UNISOC Modem Flaw Enables Remote Code Execution via Video Calls

UNISOC modem flaw enabled kernel-level code execution through video calls

zeroday.news ·

A critical vulnerability in UNISOC modem firmware could allow for arbitrary code execution with kernel privileges, potentially enabling an attacker to modify the Android kernel. The flaw, identified as Common Weakness Enumeration (CWE) 1189 for Improper Isolation of Shared Resources on System-on-a-Chip (SoC), stems from a lack of isolation between modem memory and kernel memory.

The issue was discovered by independent security researcher 0x50594d and disclosed by the SSD Secure Disclosure technical team. SSD demonstrated a full exploit chain, showing how modem-level code execution could be escalated to kernel-level execution.

The researchers explained that the missing isolation allows code running within the modem context to access memory used by the Android kernel. An attacker who has already achieved code execution on the modem can then disable protections on a Memory Protection Unit (MPU) region, granting the modem context access to physical memory, including that of the Android kernel.

SSD tested the full exploit chain against a Realme C33 running an Android security update from July 2025. This test built upon a previously disclosed UNISOC T612 RCE, demonstrating the execution of a payload in kernel space. The final stage of the attack was triggered by placing a video call to the target phone using a Voice over Long-Term Evolution (VoLTE) connection in their test environment.

Affected devices include phones utilizing UNISOC chipsets. SSD specifically listed the Xiaomi Redmi A5 with a January 1, 2026 security patch and the Motorola E13 with a February 1, 2025 security patch as examples, though they noted this is not an exhaustive list.

UNISOC, a global fabless semiconductor company specializing in mobile communication, IoT, and smart device chipsets, has not yet publicly commented on the vulnerability. SSD stated they attempted to contact UNISOC via email and LinkedIn, but no response has been reported.

For owners of affected devices, firmware updates from UNISOC and handset manufacturers are the primary means of remediation. This vulnerability highlights ongoing concerns about the security of cellular modem components, following similar risks demonstrated in other modems in recent years.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

An AI broke Snowflake's code. Then another AI agent exploited it

Don't worry, this one was via a bug bounty program

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

breach

LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected

The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more. Resecurity (USA) estimated the most affected sectors by the “SANDCLOCK” backdoor, which was planted as a result of the code repository compromise. According to cybersecurity experts, LiteLLM / TeamPCP Supply-Chain Attack will have long-lasting consequ

breach

SafePal latest crypto hardware wallet maker affected by breach, with nearly 40,000 impacted

The crypto hardware wallet company SafePal confirmed a data breach on Sunday, telling users that nearly 40,000 customers had information stolen during a recent security incident.

ai

Irregular faces criticism over ‘spin’ in AI hacking postmortem

The company at the center of a series of incidents in which AI models compromised real-world computer systems during security evaluations is facing criticism after the release of a report that security experts say leaves key questions unanswered.

breach

Poland probes MyDr healthcare software breach potentially affecting 19 million people

MyDr, a privately-owned Polish company that supplies software to doctors, clinics and other healthcare providers, said on Friday that it had identified and removed the cause of the incident and introduced additional security measures.