Skip to content

Unisoc vulnerabilities

Unisoc modem firmware appears in our reports in the context of critical remote code execution that yields full Android kernel access. The main event is researchers demonstrating a two-stage exploit chain over a VoLTE video call, where an attacker can take over a device by delivering a payload and having the victim answer the call. No specific CVE identifiers are detailed in this report, but defenders should focus on the lack of an available patch from the vendor for Unisoc-based Android devices and enhance network-level monitoring for malicious VoLTE traffic.

Azərbaycanca: Unisoc modem proqram təminatı hesabatlarımızda Android nüvəsinə tam giriş imkanı verən kritik uzaqdan kod icrası kontekstində görünür. Əsas hadisə tədqiqatçıların VoLTE video zəngi vasitəsilə iki zəifliyin zəncirvari istismarını nümayiş etdirməsidir; burada hücumçu yükləməni çatdıraraq qurbanın zəngi cavablandırması ilə cihazı ələ keçirə bilər. Bu hesabatda spesifik CVE identifikatorları təqdim olunmasa da, müdafiəçilər Unisoc modemli Android cihazları üçün təcili yamaq yeniləmələrinin olmamasına diqqət yetirməli və VoLTE trafikinə qarşı şəbəkə səviyyəsində monitorinqi gücləndirməlidirlər.

This hub is built from skopnix's own reporting on Unisoc: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.