CuraSec

Plan active

Unisoc VoLTE Exploit Chain Grants Full Android Kernel Access, No Patch

2026-08-18 11:37 UTC · The Hacker News · read the source ↗ #android#volte#baseband
  • Engineer — Plan: A published two-stage RCE-to-kernel exploit chain with no vendor fix is serious, but Unisoc chipsets are rare in US enterprise fleets. Audit your MDM inventory for Unisoc-powered devices and, if found, work with your carrier or MDM to disable VoLTE on those devices as a mitigation until a patch exists.
  • SOC/IR — Learn: The attack occurs at the baseband/modem layer via an incoming VoLTE video call, which is largely invisible to SIEM and EDR tooling. No IOCs or campaign activity are described, so there is no immediate detection or hunt action to take — file this as context on baseband attack surfaces.
  • Leader — Learn: A chipset-level mobile exploit with no fix warrants a future check on whether your mobile fleet includes Unisoc devices, but this is not a systemic or sector-wide event requiring leadership escalation today.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.