๐ต๏ธ RESEARCH & DEEP DIVES
- Unisoc VoLTE Exploit Chain Enables Full Android Kernel Access
Researchers demonstrated full Android kernel access through a Unisoc VoLTE video call exploit chain.- Affected devices use Unisoc modem firmware, including Motorola E13, Realme C33, and Xiaomi Redmi A5.
- Tested versions included Xiaomi Redmi A5 with the 2026-01-01 patch, Motorola E13 with the 2025-02-01 patch, and Realme C33 with the July 2025 update.
- A malformed SIP video call first enables code execution in the modem context.
- The exploit disables protections on MPU region 0, granting modem code read, write, and execute access across the 32-bit physical address space.
- Completing the chain requires attacker-controlled VoLTE infrastructure and a victim who answers the video call; no vendor fix was reported.
๐ Coverage: darkreading.com ยท ๐ via Dark Reading
๐ CVEs & KEV
-
CVE-2026-71424 โ CVSS 9.6 โ Onyx AI Platform Critical OAuth Token Exposure (CVE-2026-71424)
-
CVE-2026-70495 โ CVSS 8.8 โ search-v2-operator Privilege Escalation to Cluster Admin
-
CVE-2026-9816 โ CVSS 8.3 โ Insufficient server-side validation of board member role fields permits privi...
-
CVE-2026-9859 โ CVSS 6.5 โ Mattermost Boards plugin didnโt enforce role-based authorization on board cha...
-
CVE-2026-10080 โ CVSS 6.5 โ Boards plugin panics on WebSocket command with non-string field typesMattermo...