Video Call Exploit Chains Two Flaws in Unisoc Modems
BLUF
A two-flaw exploit chain allows remote device takeover via answered video calls on Unisoc-powered Android phones.
NEWS
Security researchers identified a chained vulnerability in Unisoc modem firmware that enables remote code execution. The attack requires no user interaction beyond answering an incoming video call to deliver the malicious payload. This affects Android devices utilizing Unisoc chipsets, which are common in budget and mid-range smartphones globally.
Why I Care
This flaw poses a severe risk to user privacy and device integrity, allowing attackers to install malware or steal data silently. Millions of Android users with Unisoc-based devices are potentially exposed, making it a high-priority supply chain security issue for mobile manufacturers and consumers alike.
Next Steps
Mobile vendors must patch modem firmware immediately upon vendor notification. End-users should update their device software as soon as patches are available and avoid answering unknown video calls until fixes are deployed. Security teams should monitor for Unisoc-specific CVEs and assess device inventory for affected models.
Source: Dark Reading ·