SSD Secure Disclosure reveals a two-stage exploit chain giving attackers full Android kernel access via VoLTE video calls on Unisoc devices. No patch available yet.
Security researchers at SSD Secure Disclosure just dropped a bombshell that should worry anyone using a phone with Unisoc silicon. They've published a two-stage exploit chain that starts with a simple VoLTE video call and ends with complete Android kernel access. No user interaction required. No fix from the chipset maker, either.
That's not a typo. A single incoming video call could be all an attacker needs to own your device from the kernel up. Let's break down what's happening, why it matters, and what you can actually do about it.
### The Two-Stage Attack Chain
This isn't a one-hit wonder. It's a carefully orchestrated sequence that SSD first teased back in March 2026. Stage one was remote code execution on the modem itself—the brain that handles cellular communications. That was bad enough on its own.
But stage two, published on August 17, 2026, is the real nightmare. It takes that initial foothold and escalates it to full kernel-level access on the Android side. Once an attacker controls the modem, they can pivot to the main processor and bypass every security boundary Google has built into Android.
Here's the scary part: the entire chain runs through VoLTE, which is the standard for voice calls on modern networks. You can't just turn it off and still have a usable phone in most places.
### Why This Exploit Is Different
Most mobile exploits require some form of user interaction. Maybe you click a malicious link, install a shady app, or grant a suspicious permission. Not this one. The researchers demonstrated that a video call alone is enough to trigger the chain.
Think about that for a second. Your phone rings. You answer it. That's it. The attacker now has a path to kernel access. They could theoretically read your messages, intercept your calls, access your photos, or install persistent malware that survives factory resets.
And here's the kicker: Unisoc hasn't released a patch. The advisory includes detailed technical information, but there's no fix available for affected devices. That leaves millions of phones—many in budget and mid-range segments—exposed with no timeline for remediation.
### Who's Affected
Unisoc chips power a massive chunk of the global smartphone market, especially in devices priced under $300. We're talking about phones from brands like Honor, Realme, and several others that sell heavily in the United States and abroad.
If you're not sure whether your phone uses a Unisoc processor, you can check your device settings or look up your model's specs online. The exploit specifically targets Unisoc modem firmware, so any phone with that modem is potentially vulnerable.
### What You Can Do Right Now
There's no magic bullet here, but you can take steps to reduce your risk:
- **Update your phone's firmware** the moment a patch becomes available. Check weekly, not monthly.
- **Disable video calling** if your carrier allows it. VoLTE voice calls might still be at risk, but video adds another attack surface.
- **Use a secondary device** for sensitive communications if your main phone uses a Unisoc chipset.
- **Monitor SSD's advisory** for updates. The researchers have a track record of pushing vendors to respond.
### The Bigger Picture
This exploit is a reminder that the mobile security landscape is shifting. Attackers are moving beyond app-level vulnerabilities and targeting the modem—the one component that's often overlooked in security audits.
Chipset makers like Unisoc are under pressure to improve their security practices, but progress has been slow. Meanwhile, researchers keep finding new ways to break through. The gap between discovery and patch is a dangerous window, and this case highlights just how wide that window can be.
For now, the best defense is awareness. Know what's on your phone, keep it updated, and don't assume that a "budget" device is secure just because it's cheap. The next video call you answer could be more than a conversation—it could be an intrusion.