Unresolved Unisoc Modem Flaw Lets Attackers Take Over Android Devices via Video Call
Security researchers at SSD Secure Disclosure have published details of a serious vulnerability chain affecting Android devices that use Unisoc modem chipsets. The exploit is triggered through a VoLTE video call—a standard feature used for voice and video calling over 4G/5G networks—and can ultimately grant an attacker full access to the device's operating system kernel, the deepest and most privileged layer of the software.
This is the second stage of a disclosure process that began in March 2026, when researchers first revealed a remote code execution flaw in Unisoc's modem firmware. The newly published advisory builds on that initial finding, showing how an attacker could escalate from that entry point to complete kernel-level control. Critically, Unisoc has not yet released a fix, meaning affected devices remain exposed with no official patch available at the time of publication.
Because Unisoc chipsets are widely used in budget and mid-range Android smartphones sold globally, including in markets popular with small businesses issuing low-cost devices to staff, this vulnerability could affect a meaningful number of business phones. Until a patch is released, businesses should be aware that simply receiving a video call—no user interaction required—could be enough to compromise a vulnerable device.