Unisoc modem vulnerability chain grants kernel access without vendor fix
Researchers disclosed an exploit chain affecting Unisoc modem firmware in phones sold by Motorola, Realme, and Xiaomi that could give attackers kernel access, but the chipmaker has not responded or released a patch.
Security researchers at SSD Secure Disclosure have disclosed an exploit chain that allows attackers to gain full Android kernel access on phones using Unisoc modem firmware. According to The Hacker News, the attack requires the attacker to control a private 4G network and the victim to answer an incoming VoLTE video call. The vulnerability affects at least three Unisoc chipsets found in phones including the Motorola E13, Realme C33, and Xiaomi Redmi A5, sold across more than 140 countries.
The two-stage chain began with a remote code execution disclosure in March 2026, followed by this privilege-escalation vulnerability disclosed in August 2026. SSD Secure Disclosure said it attempted to reach Unisoc through multiple channels but received no response. No patch has been released, and the August 2026 Android Security Bulletin does not address the issue. Device owners have no available mitigation and should watch for firmware updates from their manufacturer.