Video Call Exploit Chains Two Flaws in Unisoc Modems

Summary

Researchers have discovered a chain of two vulnerabilities in Unisoc modems that can be exploited to take over an Android device. The exploit requires the victim to answer a video call, which then delivers a payload to compromise the device.

IFF Assessment

FOE

This vulnerability allows attackers to gain control of a user's device through a seemingly innocuous action, posing a direct threat to user security.

Severity

9.0 Critical (AI Estimated)

Combining two vulnerabilities that lead to remote code execution and full device compromise via a common user interaction (answering a call) suggests a high CVSS score, likely in the 'Critical' range.

Defender Context

This finding highlights the critical need for timely patching of firmware and modem components, which are often overlooked in standard security practices. Defenders should monitor for advisories related to Unisoc modems and ensure devices are updated to mitigate this risk.

Read Full Story →