SSD Secure Disclosure has published a second-stage exploit for Unisoc modem firmware that turns a March 2026 remote code execution bug into full Android kernel access on T606, T612, and T7250 devices. Researchers confirmed it on patched Motorola E13 and Xiaomi Redmi A5 phones, and Unisoc has not issued a fix.
The chain starts with an answered VoLTE video call over an attacker-controlled private 4G network, then uses the modem’s memory-protection settings to mark the whole physical address space as accessible from modem context, including Android kernel memory. In plain terms, once the modem is reached, the phone’s usual software boundary no longer contains the compromise.
That matters for any Unisoc-based Android fleet where handset patch levels are assumed to contain modem-originated attacks: the exposure sits below Android, so the trust break can survive an otherwise current phone. The practical limit is targeting, not scale, because the attack needs private cellular infrastructure and a live call.