View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Unisoc VoLTE Exploit Chain Enables Full Android Kernel Access

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Unisoc VoLTE Exploit Chain Enables Full Android Kernel Access
    Researchers demonstrated full Android kernel access through a Unisoc VoLTE video call exploit chain.
    • Affected devices use Unisoc modem firmware, including Motorola E13, Realme C33, and Xiaomi Redmi A5.
    • Tested versions included Xiaomi Redmi A5 with the 2026-01-01 patch, Motorola E13 with the 2025-02-01 patch, and Realme C33 with the July 2025 update.
    • A malformed SIP video call first enables code execution in the modem context.
    • The exploit disables protections on MPU region 0, granting modem code read, write, and execute access across the 32-bit physical address space.
    • Completing the chain requires attacker-controlled VoLTE infrastructure and a victim who answers the video call; no vendor fix was reported.
      ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading

๐Ÿ”“ CVEs & KEV

  • CVE-2026-71424 โ€” CVSS 9.6 โ€” Onyx AI Platform Critical OAuth Token Exposure (CVE-2026-71424)

  • CVE-2026-70495 โ€” CVSS 8.8 โ€” search-v2-operator Privilege Escalation to Cluster Admin

  • CVE-2026-9816 โ€” CVSS 8.3 โ€” Insufficient server-side validation of board member role fields permits privi...

  • CVE-2026-9859 โ€” CVSS 6.5 โ€” Mattermost Boards plugin didnโ€™t enforce role-based authorization on board cha...

  • CVE-2026-10080 โ€” CVSS 6.5 โ€” Boards plugin panics on WebSocket command with non-string field typesMattermo...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check