In a controlled laboratory experiment, simply answering a video call was enough to trigger malicious code execution on a budget Android smartphone. Before placing the call, the researcher sent the device a series of specially crafted SIP messages. The moment the call was answered, the payload executed within the Unisoc modem itself, gained access to physical memory, and ultimately enabled modification of the Android kernel.
A Full Attack Chain Demonstrated on Real Devices
An independent researcher operating under the alias 0x50594d discovered the vulnerability within Unisoc modem firmware and demonstrated a complete end-to-end attack chain against a Realme C33 powered by the T612 chipset. SSD Secure Disclosure identified additional affected devices, including a Xiaomi Redmi A5 running a security patch dated January 1, 2026, and a Motorola E13 running a patch dated February 1, 2025.
Two Chained Vulnerabilities: Remote Code Execution and Privilege Escalation
The attack chain combines two distinct vulnerabilities. The first, disclosed in March, arises from how the modem processes SDP data embedded within SIP service messages. Specially crafted data triggers memory corruption within the modem, enabling arbitrary code execution. This flaw affects firmware running on the Unisoc T612, T616, T606, and T7250 chipsets – all of which are commonly deployed in budget smartphones.
The second vulnerability stems from a lack of memory isolation between the modem and the Android kernel. Once code executes inside the modem, an attacker can lift the restrictions imposed on region 0 within the Memory Protection Unit (MPU), gaining the ability to read and modify the device’s entire physical memory. This capability allows the attacker to overwrite kernel code directly and execute commands with the highest possible system privileges.
How the Payload Was Delivered
To deliver the exploit payload, a custom program sent the target smartphone a series of prepared INVITE requests, each containing a fragment of the exploit. Once the video call was answered, the modem processed the previously transmitted data. Supporting code located the fragments in memory, assembled the complete payload, and launched the kernel modification routine.
While the attacker could place the malicious call from any ordinary smartphone, actually launching the exploit required an additional computer. During the experiment, this computer registered itself on the laboratory’s mobile network like an ordinary subscriber device.
Demonstrated in a Controlled Lab – Real-World Feasibility Unconfirmed
The demonstration took place within a VoLTE infrastructure entirely under the researcher’s control, using smartphones with root access obtained in advance. Whether an equivalent attack could succeed over a commercial carrier’s live network has not yet been tested. Researchers have not established whether real-world mobile network infrastructure would even permit these specially crafted signaling messages to pass through unfiltered.
No Vendor Response, No CVE Assigned
SSD Secure Disclosure made repeated attempts to contact Unisoc via email and LinkedIn but received no response. The published disclosure does not include a CVE number or any information regarding a fix. The complete proof-of-concept exploit code has been made publicly available.
Scale of Potential Exposure Remains Unknown
The exact proportion of vulnerable smartphones currently in circulation remains unclear. According to Counterpoint Research, Unisoc held fourth place among smartphone chipset vendors in the first quarter of 2026, with a 14% market share. That figure, however, covers Unisoc’s entire product portfolio and does not indicate how many devices are actually affected by this specific vulnerability.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.