
Security Flaw in Unisoc VoLTE Video Calling Could Hand Attackers Complete Android Device Control
A chain of vulnerabilities in Unisoc's VoLTE video call feature may let attackers gain full control of the Android kernel, giving them deep access to the phone.
Security researchers have identified a serious vulnerability chain in the VoLTE (Voice over LTE) video call feature on Android devices that use Unisoc chipsets. If exploited, the flaw can give an attacker full access to the Android kernel, the core part of the operating system that manages the phone's hardware and security. This level of access means a remote attacker could take complete control of the device, read private data, install malicious software, and potentially intercept communications.
Unisoc is a semiconductor company that designs processors and modem chips used in many low-cost and mid-range Android phones sold worldwide. VoLTE is a technology that lets phone calls travel over the 4G or 5G data network instead of older voice networks, offering better call quality and the ability to make video calls directly from the phone dialer. The video call component of VoLTE has become a target for attackers because it processes untrusted data from incoming calls, and a flaw in that processing can be combined with other bugs to gain deeper access.
An exploit chain means that the attacker combines several smaller vulnerabilities one after another. Alone, each flaw might only cause a crash or a minor information leak. Together, they can be used to break out of the restricted environment and gain kernel-level privileges. The Android kernel is the software that acts as the bridge between apps and the phone's hardware, and it has the highest level of authority on the device. With kernel access, an attacker can bypass security sandboxes that normally keep apps and data separate, disable protections, and silently run code without the user's knowledge.
The practical consequence for a phone owner is severe. The vulnerability can be triggered through the VoLTE video call feature, which means a malicious call could be used as the delivery method. Once exploited, an attacker might be able to read SMS messages, steal one-time passcodes, turn on the camera or microphone, or use the compromised phone as a stepping stone to reach corporate networks and cloud services. For website owners and IT administrators, a compromised mobile device that holds admin credentials for a content management system or hosting account can lead to a full site takeover.
Users should check for and install system updates from their phone manufacturer or carrier as soon as they become available, because patches for the flawed code will be delivered through those updates. In the meantime, if the phone offers an option to disable VoLTE or video calling, turning it off can reduce the attack surface. Being cautious about unexpected video calls from unknown numbers is also wise, especially on devices known to use Unisoc chips. Enabling two-factor authentication on important accounts that use codes from an authenticator app, rather than SMS, can limit the damage if a device is compromised.
Although this vulnerability lives on the mobile device, it has direct consequences for online services. A website owner whose phone is compromised may lose control of hosting dashboards, DNS settings, or domain registrations. AEU DNS provides private, secure DNS for everyone, and by blocking known malicious domains that compromised devices often contact, it adds a useful layer of defense for site owners and their visitors.
How to Protect Yourself
- Check your phone for system updates and install them right away, because updates often include fixes for these security holes.
- If your phone has a setting to turn off internet-based video calling, switch it off until a fix is available.
- Do not answer video calls from numbers you do not recognise, especially if you are not expecting a call.
- Turn on two-step verification for your email and website accounts, and use a code-generating app instead of text message codes.
- Regularly back up the data on your phone so you can restore it if the device is ever taken over.