Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Summary
Security researchers have detailed a two-stage exploit chain targeting Unisoc modem firmware via VoLTE video calls, granting attackers full Android kernel access. This vulnerability remains unpatched by Unisoc, building upon a previously disclosed remote code execution flaw.
IFF Assessment
The discovery of an exploit chain that grants attackers full Android kernel access represents a significant threat to user devices and data.
Severity
This exploit chain allows for complete kernel access, a critical impact. The attack vector is over-the-air (VoLTE video call), requiring no user interaction, and it targets a widely used chipset (Unisoc). This combination points to a critical severity.
Defender Context
This vulnerability highlights the risks associated with chipset-level exploits and the need for thorough testing of modem firmware. Defenders should monitor for any patches or advisories from Unisoc and be aware of potential attack vectors targeting VoLTE functionality.