Unisoc T612 modem (and other devices on shared Unisoc modem firmware): a single answered video call can escalate from modem-level RCE to full Android kernel access via an ARM Memory Protection Unit isolation bypass; no CVE, no patch, vendor unresponsive
Answering a video call is the only user action needed to hand an attacker root-level access on affected Android devices
Analysis
Independent researcher 0x50594d, via SSD Secure Disclosure, chained two flaws in Unisoc modem firmware. The only chipset either reachable source names is the T612, demonstrated on a Realme C33; SSD also confirmed the vulnerability on a Xiaomi Redmi A5 and a Motorola E13, without either source stating which chipset those two carry. Treat the affected estate as devices on the shared Unisoc modem firmware line rather than as a closed list of three parts. Stage one, disclosed earlier in March 2026, is a memory-corruption bug in the modem's handling of SIP/SDP messages during VoLTE call setup, giving remote code execution inside the modem processor. Stage two, the new SSD finding, is an uncontrolled-recursion flaw (CWE-674) that lets code already running in the modem write a full-access configuration to the ARM Memory Protection Unit via coprocessor registers: "the new flaw that SSD Security discovered is a memory-isolation weakness in Unisoc's T612 modem's memory protection unit. The firmware flaw allows an attacker who already has access to the modem to escalate privileges and gain kernel level privileges on an affected Android device" (Dark Reading, citing SSD Secure Disclosure, 2026-08-17).
The MPU is the only hardware boundary separating modem memory from the application processor's memory, including memory used by the Android kernel; Unisoc's design shares that physical memory space between the two processors with no independent hardware enforcement beyond it. The overall attack requires an attacker-controlled position on the 4G/VoLTE network able to deliver the malformed SIP/SDP payload during call setup, and the victim simply answering an incoming video call, no other user interaction. CWE-1189 (Improper Isolation of Shared Resources on a System-on-a-Chip) is the classification given for the combined chain. No CVE identifier has been assigned, and no firmware update or mitigation is available: "the disclosure does not identify a vendor firmware update addressing the flaw" (Infosecurity Magazine, citing SSD Secure Disclosure, 2026-08-17). Unisoc did not respond to SSD's disclosure attempts, and device owners have no interim control beyond watching for a manufacturer firmware update.
Unisoc chips are concentrated in budget-tier Android devices, a segment with weaker patch cadence and longer field life; this is relevant to any BYOD or public-sector device fleet that includes low-cost handsets. No vendor fix or interim mitigation exists; the only defender-facing lever (device-fleet composition) is a standing inventory question. The transferable lesson for a device-procurement or BYOD policy is that chipset-level isolation defects can sit below any control the device's own OS vendor can patch, since the flaw is in modem firmware Unisoc alone controls, not in Android itself.
Cited evidence
The new flaw that SSD Security discovered is a memory-isolation weakness in Unisoc's T612 modem's memory protection unit. The firmware flaw allows an attacker who already has access to the modem to escalate privileges and gain kernel level privileges on an affected Android device.
The disclosure does not identify a vendor firmware update addressing the flaw.
Updates1
This entry named Unisoc T606, T612 and T7250 as the affected chipsets and paired each with one of the three test devices. That pairing is not in any source this entry can cite. Dark Reading and Infosecurity Magazine both name only the T612, and only for the Realme C33: "Researchers at SSD Secure Disclosure... demonstrated the attack chain in a controlled setting against a Realme C33 smartphone... SSD confirmed the vulnerability on a Xiaomi Redmi A5 running the January 2026 Android security patch and a Motorola E13 running the February 2025 patch" (Dark Reading, 2026-08-17), with no chipset given for the latter two. The SSD Secure Disclosure write-up itself is still unreachable, so nothing wider can be confirmed. Operationally the exposure is unchanged and if anything less bounded: the flaw sits in modem firmware shared across a product line, and an asset owner should scope by device model against the vendor's own advisory rather than by the three part numbers this entry previously listed.
Sources2
Revision history
- Published 2026-08-28T0409Z-intel
- Correction 2026-08-30T1312Z-audit
The chipset scope was overstated. This entry named Unisoc T606, T612 and T7250 as affected and mapped the three test devices one to one onto them (Motorola E13 to T606, Xiaomi Redmi A5 to T7250). Neither reachable source contains the strings T606 or T7250 anywhere: Dark Reading and Infosecurity name only the T612, and only the Realme C33 is tied to a chipset at all. The SSD Secure Disclosure primary remains behind an anti-bot challenge on every transport, so the wider chipset list cannot be traced to any readable source and has been removed from the title, summary, affected products and body.
Changed: title summary affected_products sourcing_note body
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.