CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4512

As cited

Copy frozen at (site build).

vulnerabilities

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure published a two-stage exploit chain on August 17, 2026, that achieves full Android kernel access via VoLTE video calls on devices running Unisoc modem firmware. The chain originated from a remote code execution vulnerability disclosed in March 2026, and Unisoc has not released a fix.

Why it matters: Device manufacturers and carriers using Unisoc modems face unpatched kernel-level compromise risk from VoLTE video calls; affected users should monitor device updates and consider restricting VoLTE functionality if possible until patches are released.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure published a two-stage exploit chain on August 17, 2026, that achieves full Android kernel access via VoLTE video calls on devices running Unisoc modem firmware. The chain originated from a remote code execution vulnerability disclosed in March 2026, and Unisoc has not released a fix.

Why it matters: Device manufacturers and carriers using Unisoc modems face unpatched kernel-level compromise risk from VoLTE video calls; affected users should monitor device updates and consider restricting VoLTE functionality if possible until patches are released.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure published a two-stage exploit chain on August 17, 2026, that achieves full Android kernel access via VoLTE video calls on devices running Unisoc modem firmware. The chain originated from a remote code execution vulnerability disclosed in March 2026, and Unisoc has not released a fix.

Why it matters: Device manufacturers and carriers using Unisoc modems face unpatched kernel-level compromise risk from VoLTE video calls; affected users should monitor device updates and consider restricting VoLTE functionality if possible until patches are released.

VendorsGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary