SSD Secure Disclosure demonstrates UNISOC modem remote code execution via video calls
This digest was compiled by AI from multiple sources — links to the originals are below.

SSD Secure Disclosure demonstrated a full exploit chain that extends code execution from a UNISOC modem to the Android kernel, triggered by a VoLTE video call. The flaw stems from improper isolation of shared resources on the SoC, tracked as CWE-1189. UNISOC has not responded to disclosure attempts.
Key Facts
- The vulnerability allows code running in the modem context to disable Memory Protection Unit protections and access physical memory used by the Android kernel.
- SSD tested the full chain against a Realme C33 with an Android security update from July 2025, extending modem-level execution to kernel space via a VoLTE call.
- UNISOC has not published a firmware update addressing the flaw, and SSD did not present its listed devices as an exhaustive inventory of affected phones.
- Similar risks were demonstrated in Cinterion modem components in 2024, where researchers said remote attackers were able to execute arbitrary code and manipulate device memory.
Modem Kernel Isolation Failure
SSD Secure Disclosure researchers tied the flaw to improper isolation of shared resources on the UNISOC SoC, tracked as CWE-1189. The researchers said code running in the modem context can disable Memory Protection Unit protections and access physical memory used by the Android kernel. The full chain was tested against a Realme C33 with an Android security update from July 2025. The disclosure links the test to a previously disclosed UNISOC T612 RCE and demonstrates payload execution in kernel space.
Trigger via VoLTE Video Call
SSD placed a video call to the target phone to trigger the final stage of the exploit. The test environment used a Voice over Long-Term Evolution connection to extend modem-level execution to kernel-level code execution. Affected devices include the Xiaomi Redmi A5 with a January 1, 2026 security patch and the Motorola E13 with a February 1, 2025 security patch. SSD did not identify a vendor firmware update and did not present its device list as exhaustive.
UNISOC Response Status
SSD attempted to contact UNISOC through email and LinkedIn, and Infosecurity also contacted the company for comment. No response has been received from UNISOC at the time of writing. Similar risks were demonstrated in Cinterion modem components in 2024, where researchers said remote attackers were able to execute arbitrary code and manipulate device memory. UNISOC Technologies is a top-three global fabless semiconductor company headquartered in Shanghai, specializing in 2G/3G/4G/5G mobile communication and IoT chipsets.
2 sources
SSD Secure Disclosure demonstrates UNISOC modem remote code execution via video calls



