Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Summary

Security researchers have detailed a two-stage exploit chain targeting Unisoc modem firmware via VoLTE video calls, granting attackers full Android kernel access. This vulnerability remains unpatched by Unisoc, building upon a previously disclosed remote code execution flaw.

IFF Assessment

FOE

The discovery of an exploit chain that grants attackers full Android kernel access represents a significant threat to user devices and data.

Severity

9.8 Critical (AI Estimated)

This exploit chain allows for complete kernel access, a critical impact. The attack vector is over-the-air (VoLTE video call), requiring no user interaction, and it targets a widely used chipset (Unisoc). This combination points to a critical severity.

Defender Context

This vulnerability highlights the risks associated with chipset-level exploits and the need for thorough testing of modem firmware. Defenders should monitor for any patches or advisories from Unisoc and be aware of potential attack vectors targeting VoLTE functionality.

Read Full Story →