Unisoc VoLTE Exploit Chain Delivers Full Android Kernel Access With No Vendor Fix

A two-stage exploit published by SSD Secure Disclosure achieves kernel-level compromise on Unisoc-powered Android devices via a VoLTE video call, and the chipset maker has not issued a patch.

AI-generated illustration depicting policy for the story: Unisoc VoLTE Exploit Chain Delivers Full Android Kernel Access With No Vendor Fix

Summary

  • SSD Secure Disclosure published a two-stage exploit chain on 17 August 2026 targeting Unisoc modem firmware on Android devices.
  • The attack vector is a VoLTE video call, requiring no interaction from the target beyond receiving the call.
  • The chain builds on an earlier remote code execution vulnerability disclosed by SSD in March 2026.
  • Successful exploitation yields full Android kernel access on affected devices.
  • As of publication, Unisoc has not released a fix for the vulnerability.

What Has Been Published

On 17 August 2026, researchers at SSD Secure Disclosure published details of a two-stage exploit chain targeting devices running Unisoc modem firmware. The advisory describes a complete attack path that culminates in full Android kernel access, delivered through a VoLTE video call. This is the second stage of a chain that SSD began disclosing publicly in March 2026, when the group revealed a remote code execution vulnerability in the same firmware.

How the Attack Works

The attack vector is the VoLTE video call stack within Unisoc modem firmware. The first stage, disclosed in March 2026, established remote code execution. The August advisory extends that work into a full kernel compromise — the most privileged level of access on an Android device. The sources do not detail the precise technical mechanism of each stage beyond this framing, but the implication is that an attacker who can initiate or intercept a VoLTE video call to a target device can progress from initial code execution to complete kernel control without meaningful resistance from the device.

No Patch Available

A critical detail for security teams is that Unisoc has not issued a fix as of the publication date. The advisory was made public without a corresponding vendor patch, meaning the vulnerability remains open across the installed base of affected devices. The sources do not specify which particular Unisoc chipset models or firmware versions are confirmed affected, nor do they indicate the scope of the consumer or enterprise device population carrying this firmware.

Context and Disclosure Timeline

The coordinated nature of the disclosure — building across two separate advisories over roughly five months — suggests SSD followed a staged release approach. Whether this reflects a vendor engagement process that stalled, a deliberate research publication strategy, or some combination is not clear from the available source material. What is clear is that the full attack chain is now publicly documented, raising the practical risk for any organisation with Unisoc-powered devices in its environment.

Scope Uncertainty

Unisoc chipsets are found predominantly in lower-cost Android smartphones, including some devices distributed through budget retail channels and certain government and enterprise procurement programmes in cost-sensitive markets. Security teams should not assume the exposure is limited to consumer handsets; managed device fleets acquired through value-oriented procurement may include Unisoc hardware. The sources do not confirm specific affected device models or Android versions, so organisations will need to conduct their own hardware inventory review.

Why it matters

Full kernel access means an attacker who exploits this chain owns the device entirely — data, credentials, microphone, camera, and network access are all reachable. The VoLTE vector is particularly concerning because it operates at the modem layer, below most endpoint security tooling, and may not generate signals that traditional mobile device management or endpoint detection solutions would catch. With no vendor patch available and the full exploit chain now publicly documented, the window between knowledge and active exploitation is narrowing. CISOs should treat this as an unmitigated, remotely exploitable vulnerability on any confirmed Unisoc device in their estate until Unisoc issues a fix or device vendors ship updated firmware.

What to do now

  • Conduct a hardware inventory to identify any managed or corporate-liable Android devices running Unisoc modem firmware.
  • Monitor Unisoc and device OEM security advisories for patch releases related to the VoLTE remote code execution and kernel exploit chain disclosed by SSD Secure Disclosure.
  • Review mobile device procurement policies to ensure visibility into chipset-level hardware details for devices entering your fleet.
  • Consider whether VoLTE video call functionality can be administratively restricted on confirmed Unisoc devices through carrier or MDM policy as a temporary risk reduction measure, pending clarification from the sources on whether this mitigates the vector.
  • Brief relevant stakeholders on the absence of a vendor fix so that risk acceptance decisions are made at the appropriate level.

Sources