Close Menu
GeekBlog

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Diablo 5 Just Got Announced, and This Time You Don’t Stop the Apocalypse, You Survive It

    September 14, 2026

    Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

    September 14, 2026

    A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

    September 14, 2026
    Facebook X (Twitter) Instagram Threads
    GeekBlog
    • Home
    • Mobile
    • Tech News
    • Blog
    • Gaming
    • Smartwatch
    • How-To Guides
    • AI & Software
    Facebook
    GeekBlog
    Home»Mobile»A Single Video Call Can Root Millions of Cheap Android Phones. There Is No Patch.
    Mobile

    A Single Video Call Can Root Millions of Cheap Android Phones. There Is No Patch.

    Ethan CaldwellBy Ethan CaldwellAugust 21, 202611 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Person using a smartphone in a dark room, illustrating the Unisoc modem flaw exploited through a video call
    Photo by Mikhail Nilov via Pexels
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Somebody rings your phone. It is a video call, over the mobile network rather than WhatsApp or Messenger. You do not recognize the number, but you answer anyway, because most people do. Before the picture even loads, the attacker owns the phone. Not one app, not your browser session. The kernel.

    That is the scenario a security researcher demonstrated on August 17, when SSD Secure Disclosure published the second half of an exploit chain against modem firmware used by Unisoc, the Chinese chip designer whose processors sit inside a very large share of the world’s cheapest Android phones. The first half went public back in March. Five months later there is still no patch, no CVE number, and by all accounts no reply from the vendor.

    ⚡ The short version

    • A VoLTE video call is the entry point. Malformed signaling messages corrupt memory inside the Unisoc modem before the call is even properly established.
    • The second stage escapes the modem. A weakness in the memory protection unit lets the attacker turn modem access into full Android kernel access.
    • Confirmed on real phones. The chain was demonstrated against the Xiaomi Redmi A5 and the Motorola E13. A Redmi A5 carrying the January 2026 security patch was still completely exposed.
    • No fix exists. There is no CVE, no firmware update, and SSD says it tried email and LinkedIn without getting a response from Unisoc.
    • It is not a mass attack, yet. Pulling it off requires the attacker to run their own cellular network near you, which puts this firmly in targeted territory rather than random crime.

    What Actually Happens When the Call Comes In

    Voice over LTE is not really a phone call in the old sense. It is an internet session that your carrier sets up using SIP, the same signaling protocol that runs office phone systems, with a companion format called SDP describing what kind of media the two sides intend to exchange. All of that negotiation happens inside the modem, a separate processor with its own firmware that runs alongside Android and answers to nobody.

    That separation is normally a feature. The modem is supposed to be a sealed box: it talks to the network, Android talks to the modem, and a compromise on one side is not supposed to reach the other. The March advisory broke the first half of that promise by showing that specially crafted SDP messages, sent during an ordinary incoming video call, could corrupt memory inside Unisoc’s modem firmware and get code running there. The August advisory broke the second half.

    How the chain fits together

    STEP 1

    The call arrives

    A VoLTE video call carries hostile SDP data inside normal SIP signaling.

    STEP 2

    The modem breaks

    Fragments are reassembled, memory is corrupted, and attacker code runs on the baseband.

    STEP 3

    The wall comes down

    The memory protection unit is switched off, removing the barrier between modem and Android.

    STEP 4

    Kernel access

    Android kernel memory is readable and writable. At that point the phone is not yours.

    Stage one was published in March 2026. Stage two, the modem to kernel escape, was published on August 17, 2026. Neither has been patched.

    The specific flaw in the second stage is a memory isolation weakness in the memory protection unit of the T612 modem. That component exists precisely to stop the baseband from reaching into memory it has no business touching. Once an attacker is already running code on the modem, they can disable it, and the sealed box turns out to have a door.

    Kernel access on Android is the end of the argument. Above that line sit your messages, your photos, your microphone, your camera, your location and every credential your apps have cached. Nothing you install on top of the operating system meaningfully protects you from something running underneath it.

    Which Phones Are Affected

    Recommended for you:

    Samsung Set a Date for the Galaxy S26 FE. The Only Real Upgrade Is the Chip.
    Mobile·Aug 20, 2026

    Samsung Set a Date for the Galaxy S26 FE. The Only Real Upgrade Is the Chip.

    The awkward part of this story is that the vulnerable code is not tied to one chip. It lives in modem firmware that Unisoc reuses across several processors, which is exactly why a single research effort lands on so many devices at once.

    Unisoc chipPhone used in testingStatus
    T606Motorola E13Exploit confirmed working
    T7250Xiaomi Redmi A5Exploit confirmed working
    T612Realme C33Vulnerable firmware, and the chip the second stage was written against
    T616Widely used across entry level AndroidReported in scope, shares the same firmware base

    Those four names cover an enormous amount of hardware. The T606 and T616 have been the default choice for sub $150 Android phones for years, appearing under itel, Tecno, Infinix, Realme, ZTE, Nokia and TCL badges among others. The T7250 is essentially a refreshed T612 and has been picked up widely for 2025 and 2026 budget models. Nobody has published a definitive list of every affected handset, and given that Unisoc has not acknowledged the problem, nobody is going to.

    The detail that should worry people most is not on the list above. It is that the Redmi A5 used in testing was running Xiaomi’s January 2026 security patch and was still fully exploitable. Keeping your phone updated, the advice everyone gives and almost nobody follows, would not have saved you here.

    How to find out which chip is in your phone:

    • Open Settings, About phone and look for a processor or hardware entry. Many budget phones hide it, so this often fails.
    • If it is not there, install a free hardware reader such as DevCheck, CPU-Z or Droid Hardware Info and read the SoC name on the first screen.
    • Failing both, search your exact model number, which is printed in Settings, About phone, on a specifications site. The chipset is always listed.
    • If the answer starts with Unisoc or the older brand name Spreadtrum, read the next section carefully.

    The Part Most Coverage Skipped

    Headlines about this have been apocalyptic, and the underlying research genuinely deserves the attention. But there is a condition attached that changes who should actually be worried, and it keeps getting buried.

    To run the full chain, the attacker needs to control the cellular network your phone is talking to. That means standing up a private 4G network, which in practice means a rogue base station operating within range of the target. This is not something a scammer does from a laptop in another country, and it is not going to happen to a million people at once. It is the kind of setup used against specific individuals in a specific place: a journalist at a conference, an executive in a hotel, somebody crossing a border.

    So how alarmed should you be?

    If you use a cheap Unisoc phone to call your family and check the weather, the realistic risk to you today is low. Nobody is going to park a base station outside your house.

    If you are a journalist, an activist, a lawyer or anyone whose phone would interest a well resourced adversary, and that phone runs a Unisoc chip, treat this as serious. The equipment needed for this attack costs less than a used car, and the exploit is public with no patch in sight.

    There is also a second condition worth holding onto: the victim has to answer the call. That is a genuinely useful piece of information, because it is the one part of this chain you personally control.

    Why Nobody Has Fixed It

    Android security patches follow a supply chain, and it only works when every link participates. Google publishes a monthly bulletin, but the fixes for chipset components do not come from Google. They come from Qualcomm, MediaTek, Unisoc and the rest, who write the patch, hand it to Google for the bulletin, and then wait for phone makers to fold it into their own builds and push it out.

    Remove the first link and the entire chain stops. Unisoc has not produced a patch, has not requested a CVE, and according to SSD has not answered messages sent through multiple channels. Xiaomi and Motorola cannot ship a firmware fix for code they did not write and do not control. Google cannot list a fix in a bulletin that does not exist. Everybody downstream is stuck waiting on a company that appears to have decided not to engage.

    That is a different failure from the ordinary sluggishness of Android updates. Even the slowest manufacturer eventually ships something, which is why the long wait for a new Android version is annoying rather than dangerous. Here there is nothing in the pipeline at all. The patch has not been delayed. It has not been written.

    Unisoc Is Not a Small Player Anymore

    It would be easy to file this under obscure chips in obscure phones. That framing is several years out of date.

    Global smartphone SoC share, Q1 2026

    Counterpoint Research. Unisoc is the only vendor in the top five growing at this pace.

    MediaTek 32%

    Qualcomm 23%

    Apple 19%

    Unisoc 14%, up from 10% a year ago

    Samsung 7%

    Unisoc took 14 percent of global smartphone processor shipments in the first quarter of 2026, up from 10 percent a year earlier, while both MediaTek and Qualcomm went backwards. It is now the fourth largest supplier of smartphone silicon on the planet, and its share is concentrated almost entirely at the bottom of the market, in the phones that serve as the only internet connection hundreds of millions of people have across Asia, Africa and Latin America.

    Which produces an uncomfortable symmetry. The people most likely to be carrying a vulnerable device are the least likely to have a spare phone, the least likely to be offered a firmware update, and in many cases the most likely to be worth surveilling. Cheap hardware has always come with a slower software promise, but a promise that is slow is still a promise. This one is simply absent.

    This Has Happened Before, and It Went Differently

    Unisoc’s modem has been under the microscope before. In 2022, Check Point Research reverse engineered the LTE protocol stack in a Unisoc chip and found a flaw that let a malformed packet knock out the modem entirely. It was assigned CVE-2022-20210, rated 9.4 out of 10, and Unisoc acknowledged it, scored it and patched it. Google listed the fix in the June 2022 Android bulletin. The same year, a separate researcher reported a critical issue in a preinstalled app on Unisoc devices, tracked as CVE-2022-27250.

    Recommended for you:

    Honor Built a Phone With a Robot Arm. The Catch Is You Cannot Buy It.
    Mobile·Aug 19, 2026

    Honor Built a Phone With a Robot Arm. The Catch Is You Cannot Buy It.

    The process worked. A researcher found something, the vendor answered, a number was issued, a patch shipped. Set that against 2026, where a more severe finding that reaches the kernel rather than merely crashing the modem has produced silence for five months. What changed is not the technology. It is the willingness to respond, and that is the genuinely worrying development here.

    Anyone who has followed previous flaws that cut across a large slice of the Android install base will recognize the pattern. Wide reach and slow vendor response are what turn an interesting piece of research into a practical problem for ordinary people.

    What You Can Actually Do

    Practical steps, in order of usefulness:

    • Do not answer cellular video calls from numbers you do not know. This is the whole entry point, it costs you nothing, and it is the only mitigation that works today. Let it ring out and see if a message follows.
    • Consider turning VoLTE off if your carrier still supports fallback. Look under Settings, Network and internet, SIMs. Be aware this can degrade call quality or break calling outright on networks that have retired 3G, so test it before you rely on it.
    • Take every firmware update your manufacturer offers. A fix cannot reach you any other way, and if Unisoc does eventually respond, this is how it will arrive.
    • Use encrypted apps for sensitive calls. Signal, WhatsApp and similar do not touch the VoLTE stack at all, so they sidestep this attack surface completely.
    • If your threat model is real, change the hardware. No configuration change fixes unpatched firmware. Phones from vendors with published multi year support commitments, including Google’s current Pixel lineup, exist precisely because this scenario keeps happening.

    The Lesson Is About Accountability, Not Chips

    Every processor has bugs. Qualcomm has shipped baseband flaws, Samsung’s Exynos modem had a notorious run of them, and Apple patches its cellular stack regularly. Finding a vulnerability in a modem is not an indictment of a company. It is Tuesday.

    What separates a manageable problem from a lasting one is whether somebody picks up the phone. A vendor that answers researchers, issues CVEs and ships firmware turns a scary headline into a footnote within a month. A vendor that does not turns the same headline into a permanent condition of owning the device, and leaves manufacturers and users with no move to make.

    Right now, hundreds of millions of phones are in that second category. If yours is one of them, the sensible response is not panic. It is to stop answering video calls from strangers, and to keep in mind, when you buy the next one, that the cheapest phone on the shelf comes with a support policy you never see printed on the box.

    Android Motorola Security
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Previous ArticleFortnite Went Dark Overnight and Came Back With Sonic, Mega Man and a Button That Rewrites the Match
    Next Article ChatGPT Just Hit 1 Billion Weekly Users. It’s Losing the Market Anyway.
    Ethan Caldwell

      Ethan Caldwell is GeekBlog's resident Apple specialist, covering the entire Apple ecosystem - iPhone, iPad, Mac, Apple Watch, AirPods and the software that ties them together. A longtime iOS user and gadget collector, Ethan tracks Cupertino's every move, breaking down Apple keynotes, A- and M-series chip benchmarks, iOS feature updates and the rumor mill into clear, practical takes that help readers decide whether the latest Apple hardware is worth the upgrade.

      Related Posts

      9 Mins Read

      Android Can Finally Fight Car Sickness. Apple Shipped the Same Idea Two Years Ago.

      9 Mins Read

      Apple Called It a Huge Battery Leap. The EU Label Shows Only One iPhone Got It.

      6 Mins Read

      Apple Revealed Burgundy on Wednesday. Android Phones in Almost the Same Shade Were Already on Sale.

      8 Mins Read

      Anthropic Banned Five Groups of Working Scientists. It Says It Cannot Prove Any of Them Meant Harm.

      6 Mins Read

      Google Made Its Best Paid Gemini Feature Free. The Price Is Access to Your Inbox.

      8 Mins Read

      Anthropic Blamed a Bug When Claude Hacked Real Companies. Now It Says the Model Talked Itself Into It.

      Top Posts

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20264 Views

      Every iPhone Camera Ranked in 2026 (Best to Worst)

      July 6, 20263 Views

      The Mesh Router Placement Strategy That Finally Gave Me Full Home Coverage

      September 9, 20262 Views
      Stay In Touch
      • Facebook

      Subscribe to Updates

      Get the latest tech news from FooBar about tech, design and biz.

      Most Popular

      How to Change HEIC to JPG on iPhone, Mac, Android and Windows (No Software Needed)

      September 3, 20266 Views

      Gal Gadot’s Lawyers Spent Six Months on One AI Clause. Then SAG Called Them for Pointers.

      September 2, 20265 Views

      How to Spot AI Generated Images in 2026 (The Old Tricks Stopped Working)

      September 3, 20263 Views
      Our Picks

      Diablo 5 Just Got Announced, and This Time You Don’t Stop the Apocalypse, You Survive It

      September 14, 2026

      Meta Spent Three Years Flattening Management for AI. Now It’s Rebuilding the Layer It Cut.

      September 14, 2026

      A Hacker Ran Hundreds of AI Agents at Once. GreyNoise Says It Breached 440 Servers in Four Hours.

      September 14, 2026

      Subscribe to Updates

      Get the latest creative news from FooBar about art, design and business.

      HEICJPG.online - Convert HEIC to JPG online
      Facebook
      • About Us
      • Contact us
      • Privacy Policy
      • Disclaimer
      • Terms and Conditions
      • Editorial Policy
      • Cookie Policy
      © 2026 GeekBlog

      Type above and press Enter to search. Press Esc to cancel.