<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Volte on CuraSec</title><link>https://curasec.metacog.co.kr/tags/volte/</link><description>Recent content in Volte on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 11:37:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/volte/index.xml" rel="self" type="application/rss+xml"/><item><title>Unisoc VoLTE Exploit Chain Grants Full Android Kernel Access, No Patch</title><link>https://curasec.metacog.co.kr/insights/2026-08-18-unisoc-volte-video-call-exploit-chain-can-give-attackers-ful/</link><pubDate>Tue, 18 Aug 2026 11:37:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-18-unisoc-volte-video-call-exploit-chain-can-give-attackers-ful/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> A published two-stage RCE-to-kernel exploit chain with no vendor fix is serious, but Unisoc chipsets are rare in US enterprise fleets. Audit your MDM inventory for Unisoc-powered devices and, if found, work with your carrier or MDM to disable VoLTE on those devices as a mitigation until a patch exists.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The attack occurs at the baseband/modem layer via an incoming VoLTE video call, which is largely invisible to SIEM and EDR tooling. No IOCs or campaign activity are described, so there is no immediate detection or hunt action to take — file this as context on baseband attack surfaces.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A chipset-level mobile exploit with no fix warrants a future check on whether your mobile fleet includes Unisoc devices, but this is not a systemic or sector-wide event requiring leadership escalation today.&lt;/li>
&lt;/ul></description></item></channel></rss>