Executive Summary
In August 2026, researchers at SSD Secure Disclosure identified a critical security vulnerability in Unisoc's T612 modem firmware. By chaining a previously disclosed remote code execution (RCE) flaw with a newly discovered memory isolation weakness, attackers can gain privileged access to the Android kernel on affected devices. The exploit involves delivering a malicious payload to the modem and then initiating a video call, which the victim must answer to trigger the attack. This vulnerability impacts devices from manufacturers such as Realme, Xiaomi, and Motorola, leaving millions of users at risk.
The significance of this discovery lies in the increasing prevalence of sophisticated attack chains targeting mobile devices. As threat actors continue to exploit firmware-level vulnerabilities, it underscores the necessity for robust security measures and timely firmware updates to protect user data and device integrity.
Why This Matters Now
This incident highlights the urgent need for mobile device manufacturers to prioritize firmware security and establish effective communication channels with security researchers. The lack of timely patches for such critical vulnerabilities exposes users to potential remote exploitation, emphasizing the importance of proactive security practices in the rapidly evolving mobile landscape.
Attack Path Analysis
An attacker exploited a remote code execution vulnerability in the Unisoc T612 modem by sending specially crafted SIP/SDP messages, allowing them to execute arbitrary code on the modem. Subsequently, the attacker leveraged a memory isolation weakness in the modem's firmware to escalate privileges and gain kernel-level access on the Android device. With elevated privileges, the attacker could move laterally within the device, potentially accessing sensitive data and other applications. The attacker established a command and control channel to remotely control the compromised device. Sensitive data was exfiltrated from the device to an external server controlled by the attacker. The attacker could perform actions such as installing additional malware, disrupting device functionality, or further compromising user data.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
An attacker exploited a remote code execution vulnerability in the Unisoc T612 modem by sending specially crafted SIP/SDP messages, allowing them to execute arbitrary code on the modem.
Related CVEs
CVE-2025-31718
CVSS 7.5Improper input validation in the modem firmware of Unisoc chipsets allows remote escalation of privilege, potentially leading to system crashes.
Affected Products:
Unisoc T606 – Android13, Android14, Android15, Android16
Unisoc T612 – Android13, Android14, Android15, Android16
Unisoc T616 – Android13, Android14, Android15, Android16
Unisoc T750 – Android13, Android14, Android15, Android16
Unisoc T765 – Android13, Android14, Android15, Android16
Unisoc T760 – Android13, Android14, Android15, Android16
Unisoc T770 – Android13, Android14, Android15, Android16
Unisoc T820 – Android13, Android14, Android15, Android16
Unisoc S8000 – Android13, Android14, Android15, Android16
Unisoc T8300 – Android13, Android14, Android15, Android16
Unisoc T9300 – Android13, Android14, Android15, Android16
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Exploit via Radio Interfaces
Exploitation for Client Execution
Exploitation for Privilege Escalation
Exfiltration Over Alternative Protocol
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Mobile device exploitation targeting Unisoc modem firmware creates critical vulnerabilities in cellular network infrastructure, affecting carrier operations and subscriber security across Android devices.
Consumer Electronics
Unisoc T612 chipset vulnerabilities impact multiple smartphone manufacturers including Motorola, Samsung, Realme, Nokia, and ZTE, requiring immediate firmware updates and device security assessments.
Computer Hardware
Memory isolation weaknesses in semiconductor designs expose kernel-level access risks, highlighting critical security gaps in mobile chipset architecture and hardware-based protection mechanisms.
Wireless
Video call exploit chains compromise 4G/VoLTE networks through SIP/SDP protocol manipulation, creating remote code execution risks requiring enhanced wireless security controls and monitoring.
Sources
- Video Call Exploit Chains Two Flaws in Unisoc Modemshttps://www.darkreading.com/mobile-security/video-call-exploit-chains-two-flaws-unisoc-modemsVerified
- Unisoc Product Security Bulletinhttps://www.unisoc.com/en/support/product-security-bulletin/1976557615080263681Verified
- CVE-2025-31718: CWE-20 Improper Input Validation in Unisoc Modemshttps://radar.offseq.com/threat/cve-2025-31718-cwe-78-os-command-injection-in-unis-6bf0c291Verified
- Critical UNISOC T612 Modem Flaw Enables Remote Code Execution via Cellular Callshttps://www.planetjon.net/news/cybersecurity/critical-unisoc-t612-modem-flaw-enables-remote-code-execution-via-cellular-calls/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally within the device and exfiltrate sensitive data, thereby reducing the overall blast radius.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access to the modem would likely remain unaffected, as CNSF primarily focuses on post-compromise containment rather than preventing initial exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may be constrained, limiting their control over the device and reducing the potential impact of the attack.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the device would likely be restricted, reducing their ability to access sensitive data and other applications.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels may be hindered, reducing their capacity to remotely control the compromised device.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's capacity to inflict further damage would likely be limited, reducing the overall impact on the device and user data.
Impact at a Glance
Affected Business Functions
- Mobile Communications
- Data Services
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of user data due to remote code execution.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline intrusion prevention systems (IPS) to detect and block malicious SIP/SDP messages targeting known vulnerabilities.
- • Apply security updates promptly to address known vulnerabilities in modem firmware and other device components.
- • Utilize zero trust segmentation to limit lateral movement within devices, restricting access to sensitive data and applications.
- • Deploy egress security and policy enforcement mechanisms to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance threat detection and anomaly response capabilities to identify and respond to unusual device behavior indicative of compromise.



