Video Call Exploit Chains Two Flaws in Unisoc Modems to Take Over Android Devices
What Happened — Researchers demonstrated that two separate vulnerabilities in Unisoc modem firmware can be chained together. By delivering a malicious payload during a video‑call session and coaxing the target to answer the call, an attacker can gain full control of the Android device.
Why It Matters for Compliance & Audit Readiness
- The scenario mirrors a classic SOC 2 access‑control failure: an attacker bypasses logical controls and gains unauthorized system access.
- Continuous evidence of device‑level controls (mobile‑device‑management policies, firmware‑update verification, and user‑awareness training) is required to demonstrate compliance with the SOC 2 CC6.1 “Logical Access” control.
- Verisq’s SOC 2 Access Controls capability helps map these technical safeguards to audit‑ready evidence and supports ongoing security‑awareness programs.
Who Is Affected — Mobile‑device manufacturers, telecom OEMs, enterprises with BYOD programs, and any organization that relies on Unisoc‑based Android devices (healthcare, finance, retail, etc.).
Recommended Actions
- Inventory all devices using Unisoc chipsets and verify firmware version.
- Apply any vendor‑issued patches or mitigations immediately.
- Strengthen MDM policies to enforce signed‑firmware updates and restrict unsolicited video‑call traffic.
- Incorporate this exploit scenario into security‑awareness training and phishing simulations.
Source: Dark Reading
Technical Notes
- The chain combines a remote‑code‑execution flaw in the modem’s baseband processor with a social‑engineering step that forces the user to answer a malicious video call.
- No public CVE identifiers were disclosed at the time of reporting; the vulnerabilities are considered zero‑day until patched.
- Impacted data includes full device control, access to contacts, messages, location, and any enterprise apps running on the device.
Source: Dark Reading