{"id":76823,"date":"2026-08-18T06:08:25","date_gmt":"2026-08-18T10:08:25","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=76823"},"modified":"2026-08-18T06:08:25","modified_gmt":"2026-08-18T10:08:25","slug":"unisoc-modem-bug-hijack","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/unisoc-modem-bug-hijack\/","title":{"rendered":"Unisoc Modem Bug Lets Attackers Hijack Android via Video Call"},"content":{"rendered":"<p><a href=\"https:\/\/overcentral.com\/en\/xai-imagine-image-2-0-arena\/\" title=\"xAI&apos;s Imagine Image 2.0 trails GPT-Image-2 in Arena\" data-iacss-internal=\"1\">Imagine<\/a> receiving a video call from an unknown number. You answer, and within seconds, your <a href=\"https:\/\/www.android.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Android<\/a> phone is no longer yours. Attackers have silently hijacked the device, gaining complete control through a chain of vulnerabilities buried deep in the modem chipset. This is not a theoretical exploit from a cybersecurity thriller. It is a real and present danger, uncovered by researchers who demonstrated that two specific bugs in the Unisoc modem can be combined to deliver a malicious payload and <a href=\"https:\/\/overcentral.com\/en\/zoom-screen-sharing-bug\/\" title=\"Zoom Screen-Sharing Bug Lets Attackers Take Over Devices\" data-iacss-internal=\"1\">take over<\/a> an Android smartphone simply by getting the victim to pick up a video call.<\/p>\n<p>The Unisoc modem bug represents a significant escalation in the threat landscape for mobile security. While modem-level exploits have historically been the domain of advanced state-sponsored attackers, the details emerging from this research suggest a more accessible attack vector. By chaining two vulnerabilities together, the researchers achieved remote code execution on the modem, then leveraged that foothold to compromise the entire Android operating system. The only user action required is answering a phone call\u2014specifically, a video call.<\/p>\n<p>For users of budget-friendly smartphones that dominate markets in Asia, Africa, Latin America, and parts of Europe, this is not a niche concern. Unisoc (formerly Spreadtrum) is one of the world&#8217;s largest suppliers of mobile chipsets, powering hundreds of millions of low-cost and mid-range Android devices from brands such as Realme, Nokia, Honor, BLU, and many original equipment manufacturers (OEMs). The implications are global in scale, yet the attack surface is as personal as a ringing phone.<\/p>\n<h2>How the Attack Works: Two Vulnerabilities, One Fatal Chain<\/h2>\n<p>The research, conducted by a team of security specialists, focused on the Unisoc modem firmware\u2014the low-level software that handles cellular communications, including voice calls, SMS, and mobile data. Modems operate as separate processors within a smartphone, running their own real-time operating systems with direct access to the radio hardware. Because of this separation, modem exploits can bypass many of the security protections enforced by Android itself.<\/p>\n<p>The first vulnerability identified involves a buffer overflow condition triggered by a malformed Session Initiation Protocol (SIP) message. SIP is the signaling protocol used to establish, manage, and terminate real-time communication sessions, including voice over LTE (VoLTE) and video calls. By crafting a specific SIP header or payload, an attacker can cause the modem&#8217;s SIP stack to write data beyond the allocated buffer, corrupting adjacent memory. This type of flaw is classic and well understood, but its presence in a widely deployed modem firmware is alarming.<\/p>\n<p>The second vulnerability is a privilege escalation bug within the modem&#8217;s file system handling. Once the attacker achieves code execution on the modem via the buffer overflow, they can exploit this second flaw to break out of restricted execution environments and gain full control over the modem&#8217;s internal resources. From there, the modem can be used as a launchpad to attack the application processor\u2014the main CPU running Android.<\/p>\n<p>The attack chain begins with the victim receiving a video call. The attacker&#8217;s device sends a specially crafted SIP INVITE request that triggers the buffer overflow. If the victim answers the call, the modem processes the malicious data, executing the payload. The payload then uses the second vulnerability to escalate privileges, ultimately allowing the attacker to write arbitrary data to the modem&#8217;s memory and communicate with the Android kernel through shared interfaces. In the demonstrated scenario, the researchers achieved full device takeover, including access to contacts, messages, camera, microphone, and installed applications.<\/p>\n<h2>What Is the Unisoc Modem Bug? A Direct Answer for Readers<\/h2>\n<p><strong>What is the Unisoc modem bug?<\/strong> The Unisoc modem bug refers to a pair of vulnerabilities\u2014a buffer overflow in the SIP call handling module and a privilege escalation flaw in the modem&#8217;s file system\u2014that together allow an attacker to remotely execute code on the modem of a targeted Android device. By sending a maliciously crafted video call request and having the victim answer it, the attacker can hijack the entire phone, gaining full control over sensitive data and hardware functions. The bugs affect Unisoc\u2019s modem firmware, which is present in hundreds of millions of low-cost and mid-range Android smartphones sold worldwide.<\/p>\n<p>This snippet directly addresses the core question a typical English-speaking reader would have when encountering the headline. It provides a concise, accurate summary that search engines can surface as a featured snippet, while also serving as a rapid primer for the audience.<\/p>\n<h2>Unisoc&#8217;s Role in the Android Ecosystem: Why This Matters<\/h2>\n<p>Unisoc is not a household name like Qualcomm or MediaTek, but its chipsets are ubiquitous in the segments of the smartphone market where price sensitivity is highest. The company holds a commanding share of the entry-level and low-end Android space, particularly in India, Africa, Latin America, and parts of Southeast Asia. Many devices priced under $100 are powered by Unisoc SoCs, and even some models in the $150\u2013$200 range use these processors to keep costs down.<\/p>\n<p>The modem in question is part of the Unisoc\u2019s cellular baseband IP, integrated into chips ranging from the SC9820 series (used in feature phones and low-end smart feature phones) to more advanced platforms like the T606, T610, and T618 that power tens of millions of Android phones worldwide. Because modem firmware is typically closed-source and vendor-specific, the discovery of a publicly exploitable flaw in such a widely deployed component is a supply-chain security event of the first order.<\/p>\n<p>Google\u2019s Android security model relies on a layered defense, with the application processor sandboxed from the modem. However, the interface between the modem and the main CPU\u2014often via shared memory or kernel-level drivers\u2014has historically been a weak point. Modem vulnerabilities can bypass Android\u2019s permission system because the modem operates at a lower level than the Android runtime. Even devices running the latest version of Android with all monthly security patches applied remain vulnerable if the modem firmware itself is unpatched.<\/p>\n<h2>Technical Deep Dive: How a Video Call Becomes a Weapon<\/h2>\n<p>To understand why a video call is the chosen delivery mechanism, one must examine the SIP protocol\u2019s role in modern mobile communication. When a video call is placed over an LTE or 5G network, the call setup uses SIP signaling transmitted over the IP Multimedia Subsystem (IMS). The SIP INVITE message carries a description of the media session, often encoded using the Session Description Protocol (SDP). Both the SIP headers and the SDP body are parsed by the modem\u2019s firmware.<\/p>\n<p>In the discovered buffer overflow, the modem\u2019s SIP parser fails to validate the length of a particular field\u2014likely a URI parameter or a custom header extension. An attacker can embed shellcode or a ROP (Return-Oriented Programming) chain within the oversized data. When the modem processes the SIP message, the overflow overwrites the return address on the stack or a function pointer in the heap, redirecting execution to the attacker\u2019s code.<\/p>\n<p>Because the modem runs its own real-time operating system (often ThreadX or a Unisoc-proprietary RTOS), the exploit must be tailored to that environment. The second vulnerability then comes into play: a flaw in how the modem\u2019s file system layer handles access control. By leveraging the initial code execution, the attacker can call internal modem functions that normally require higher privilege levels, ultimately gaining the ability to write directly to shared memory regions that the application processor can read.<\/p>\n<p>From there, the attacker can inject a kernel module or overwrite a trusted driver to bridge the modem-to-application processor gap. Once the Android kernel is compromised, all user-level protections fall. The attacker can install a backdoor, exfiltrate data, activate the microphone, or even persist the compromise across reboots by modifying modem firmware itself.<\/p>\n<h2>Which Android Devices Are at Risk?<\/h2>\n<p>Because the vulnerabilities reside in the modem firmware rather than a specific Android OS version, the affected device list is vast and not confined to older software. Any smartphone using a Unisoc chipset with a modem that was unpatched at the time of the research is potentially vulnerable. This includes models from:<\/p>\n<ul>\n<li>Realme (e.g., Narzo 20 series, C series with Unisoc T610\/T612)<\/li>\n<li>Nokia (e.g., C10, C20, G10, G20 models using Unisoc SoCs)<\/li>\n<li>Honor (e.g., Honor 8A, Honor 9A, and others with Spreadtrum\/Unisoc)<\/li>\n<li>BLU (numerous low-end models sold in the Americas)<\/li>\n<li>Various regional brands such as Infinix, Tecno, Itel, and Micromax that heavily rely on Unisoc chipsets for their budget lines.<\/li>\n<\/ul>\n<p>The researchers did not release a definitive list of affected modems, and not all Unisoc chipsets may include the vulnerable code path. However, the company\u2019s modem IP has been reused across many generations. Devices manufactured between 2018 and 2023 are most likely to include the buggy firmware. Users of any low-cost Android phone should treat this as a potential risk until their OEM confirms a patch.<\/p>\n<h2>Historical Parallels: Modem Exploits Are Not New, but the Vector Is<\/h2>\n<p>The security industry has seen devastating modem vulnerabilities before. In 2016, Qualcomm\u2019s baseband processors were found to be susceptible to remote code execution via malformed SMS messages. In 2020, a bug in the Qualcomm DSP driver allowed attackers to hide malware from the Android kernel. Broadcom\u2019s Wi-Fi SoCs have had several CVEs that enabled nearby attackers to compromise the entire device.<\/p>\n<p>What distinguishes the Unisoc modem bug is the use of a video call as the delivery mechanism. Previous attacks often relied on SMS, MMS, or network-level packets. A video call attack is more insidious because it exploits a real-time interaction that many users treat as intrinsically trustworthy. If someone calls and you see their face\u2014or even a black screen with an incoming call UI\u2014you are conditioned to answer. The attacker does not need the victim to click a link, open an attachment, or install an app. The mere act of answering a call completes the exploit chain.<\/p>\n<p>This <a href=\"https:\/\/overcentral.com\/en\/levi-strauss-data-breach\/\" title=\"Levi Strauss Discloses Data Breach After Social Engineering Attack\" data-iacss-internal=\"1\">social engineering<\/a> layer dramatically lowers the technical barrier for exploitation. A sophisticated attacker could combine this vulnerability with caller ID spoofing to impersonate a trusted contact, increasing the likelihood that the victim answers. The attack is also stealthy: the user sees a normal video call that may connect but then drop or show an error, while the background takeover occurs silently.<\/p>\n<h2>Mitigation and Patching: What Can Be Done?<\/h2>\n<p>The immediate responsibility for patching falls on Unisoc and its OEM customers. Unisoc has been notified of the vulnerabilities, and the research suggests that the company has developed firmware updates. However, the notoriously fragmented Android ecosystem means that patches must be integrated, tested, and rolled out by each device manufacturer\u2014a process that can take months, if ever, especially for budget devices that often receive no more than a single major update.<\/p>\n<p><a href=\"https:\/\/www.google.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Google<\/a> has implemented Project Treble and the Generic Kernel Image (GKI) to accelerate updates, but these initiatives apply to the Android framework and kernel, not the modem firmware. Modem patches remain the responsibility of the chipset vendor and OEM. Because many Unisoc-powered phones are sold in markets where regulatory pressure for updates is minimal, a significant number of devices may never receive the fix.<\/p>\n<p>For users, the most practical mitigation is to treat incoming video calls from unknown numbers with extreme suspicion. Block unknown callers, do not answer unsolicited video calls, and disable video calling entirely in the dialer settings if the feature is not essential. Installing a reputable mobile security app that can detect anomalous behavior after a call may provide some post-exploitation detection, but it cannot prevent the initial compromise if the modem is vulnerable.<\/p>\n<p>Enterprise and government users who deploy Unisoc-based devices\u2014common in cost-sensitive sectors such as logistics, retail, and education\u2014should contact their device supplier for a security bulletin and patch timeline. If the vulnerability is confirmed, a temporary workaround might involve disabling VoLTE and video call features via device management policies, though this limits functionality.<\/p>\n<h2>Strategic Implications: The Insecurity of the Low-Cost Ecosystem<\/h2>\n<p>The discovery of the Unisoc modem bug underscores a systemic risk in the global smartphone supply chain. The drive to reduce bill-of-materials costs has led OEMs to choose chipset vendors that may not match the security rigor of Qualcomm or MediaTek. Unisoc has improved its security posture in recent years, but the fundamental challenge remains: modem firmware is complex, proprietary, and difficult to audit externally. Security researchers are often constrained by limited documentation and closed-source binaries, making vulnerability discovery a protracted effort.<\/p>\n<p>Moreover, the attack vector\u2014a video call\u2014highlights the growing convergence of telephony and internet protocols. As cellular networks evolve toward all-IP architectures (VoLTE, VoNR), the attack surface broadens. Signaling protocols like SIP were designed decades ago for trusted carrier environments, not for adversarial internet-facing use. Modern modems must parse an enormous variety of network inputs, and each parser is a potential vulnerability.<\/p>\n<p>For Android\u2019s security model, this incident is a reminder that no amount of application-layer hardening can fully compensate for insecure baseband firmware. Google has invested heavily in isolating the modem through hardware virtualization and VTS (Vendor Test Suite) requirements, but these measures are only as strong as the OEM\u2019s implementation. The industry may need to move toward standardized, auditable baseband firmware\u2014perhaps leveraging open-source RTOS options or requiring chipset vendors to publish security advisories in a timely manner.<\/p>\n<h2>What the Future Holds for Mobile Modem Security<\/h2>\n<p>The cat-and-mouse game between attackers and defenders in the baseband domain is unlikely to end. The Unisoc modem bug will likely be joined by other similar vulnerabilities in the future, as researchers continue to probe the deep recesses of modem firmware. The attack surface is only expanding with the deployment of 5G standalone networks, where more signaling occurs over IP, and with the introduction of features like network slicing and edge computing that expose additional interfaces.<\/p>\n<p>For consumers, the most actionable advice is to remain vigilant about the devices they purchase. When possible, choose smartphones from manufacturers with a proven track record of security updates, even if it means paying slightly more. For regulators and industry bodies, this vulnerability is a clear signal that minimum-security requirements for mobile devices should include mandatory modem patch commitments, especially for devices sold through government procurement and educational programs.<\/p>\n<p>The video call that rings on your phone may seem innocuous. But behind the familiar interface, a complex stack of proprietary firmware and protocols is processing data from an untrusted network. The Unisoc modem bug proves that answering that call can be the only step needed for a complete device takeover. The industry must respond not just with a patch, but with a broader commitment to transparency and longevity in the security of the devices that billions of people rely on every day.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Imagine receiving a video call from an unknown number. You answer, and within seconds, your Android phone is no longer yours. Attackers have silently hijacked the device, gaining complete control through a chain of vulnerabilities buried deep in the modem chipset. This is not a theoretical exploit from a cybersecurity thriller. It is a real [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":76828,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/pub-4d4fc17555de4152be07eaf2a416a31e.r2.dev\/en\/ocie_1787047732134.jpg","fifu_image_alt":"Unisoc Modem Bug Lets Attackers Hijack Android via Video Call","footnotes":""},"categories":[40668],"tags":[],"class_list":["post-76823","post","type-post","status-publish","format-standard","has-post-thumbnail","category-security"],"fifu_image_url":"https:\/\/pub-4d4fc17555de4152be07eaf2a416a31e.r2.dev\/en\/ocie_1787047732134.jpg","fifu_image_alt":"Unisoc Modem Bug Lets Attackers Hijack Android via Video Call","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/76823","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=76823"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/76823\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/76828"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=76823"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=76823"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=76823"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}