Unisoc VoLTE Video Call Exploit Chain Achieves Full Android Kernel Access
Researchers disclose second stage of two-stage attack targeting Unisoc modem firmware; no patch available

Key Takeaways
- A two-stage exploit chain targeting Unisoc modem firmware achieves full Android kernel access via VoLTE video call.
- The first stage, disclosed in March 2026, provided remote code execution; the second stage, disclosed August 17, 2026, escalates to kernel-level privileges.
- Unisoc has not provided a patch or mitigation as of the advisory publication.
Related Security News

Hackers exploit Citrix NetScaler zero-day to deploy web shells
Cybersecurity firms report that attackers are exploiting a zero-day vulnerability in Citrix NetScaler to deploy custom web shells and tunneling malware. The exploitation grants root access, enables credential theft, and facilitates lateral movement into internal networks. Citrix has released patches and security advisories addressing CVE-2026-88772.



