Unisoc VoLTE Video Call Exploit Chain Grants Full Android Kernel Access
What Happened — Researchers at SSD Secure Disclosure released a two‑stage exploit chain that, when a victim receives a VoLTE video call on an Android device powered by Unisoc modem firmware, allows an attacker to execute arbitrary code and obtain full kernel privileges. The first stage was disclosed in March 2026; the second stage, published August 2026, completes the chain and the chipset maker has not issued a fix.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a classic third‑party component risk that SOC 2 vendor‑management controls are designed to identify, assess, and monitor.
- Continuous evidence of firmware‑vulnerability tracking is essential to prove due diligence during an audit.
- Mapping this flaw to CC6.1 (System Operations) and CC7.2 (Change Management) provides a defensible audit trail if a breach occurs.
Who Is Affected — Mobile device manufacturers, telecom operators, and enterprises that allow BYOD or manage Android fleets with Unisoc‑based hardware.
Recommended Actions
- Inventory all devices that use Unisoc modems.
- Add the Unisoc firmware issue to your vendor‑risk register and track remediation status.
- Deploy mobile‑device‑management policies that can block VoLTE video calls or enforce quarantine until a patch is available.
- Map the finding to SOC 2 controls (CC6.1, CC7.2) and collect evidence of mitigation for audit readiness. Source: The Hacker News
Technical Notes
- Attack vector: VoLTE video call triggers a two‑stage exploit in Unisoc modem firmware, leading to remote code execution and full kernel privilege escalation on Android.
- No CVE identifier disclosed; the chipset maker has not released a patch as of the advisory date. Source: The Hacker News