Unisoc Chip Vulnerability in VoLTE Video Calls Could Give Attackers Complete Android Control

Unisoc Chip Vulnerability in VoLTE Video Calls Could Give Attackers Complete Android Control

A newly reported exploit chain targeting Unisoc processors via VoLTE video calls may allow attackers to gain full kernel access on Android devices.

A serious security issue has come to light involving a widely used family of mobile processors. The problem affects Android devices built around Unisoc chipsets, which power many budget and mid-range smartphones, especially in Europe and emerging markets. According to the report, an attacker can trigger the issue through a VoLTE video call, which is a video call placed over the 4G or 5G data network rather than a traditional voice network. By sending a specially crafted call or media stream, the attacker could exploit a chain of software flaws to reach the kernel, the most privileged part of the Android operating system. Once an attacker controls the kernel, they effectively control everything on the phone: files, cameras, microphones, saved passwords, and access to online accounts.

To understand the severity, it helps to know what VoLTE and the kernel are. VoLTE stands for Voice over LTE, where LTE is the high-speed data network used by modern smartphones. Instead of making a call over the older, separate voice network, VoLTE carries the call as data, which allows features like higher-quality audio and video calls. The kernel is the core of the Android operating system; it sits between applications and the phone's hardware, managing memory, processes, and security boundaries. Normally, a video call app runs in a restricted area and cannot touch critical system files. An exploit chain is a series of carefully ordered attacks that break through these restrictions one by one, moving from a minor flaw in the call handling code to a complete takeover. In this case, the starting point is apparently the video call feature built into phones using Unisoc processors.

For everyday phone users, this kind of attack is particularly dangerous because it can happen without any action beyond receiving a call. A victim may not even need to answer the call in some scenarios, depending on how the phone processes incoming video call signaling. That means an attacker could potentially compromise a phone silently, then steal credentials, read messages, or install additional malware. For website owners and IT teams, the risk extends to the websites and services they manage. If an employee's phone is compromised and that phone is used to access a website admin panel, hosting control panel, or cloud dashboard, the attacker may capture login credentials or even bypass multi-factor authentication if the second factor is delivered to the same phone. A compromised mobile device can serve as a bridge into corporate infrastructure.

At the time of writing, the full technical details and any associated CVE identifiers have not been included in the public source. That means affected users cannot yet refer to a specific patch or mitigation. However, the underlying issue has been disclosed publicly through security channels, and researchers often coordinate with the chipset vendor before publishing proof-of-concept code. Unisoc is known to supply processors to many phone brands, so the potential number of affected devices could be large. Users should watch for security updates from their device manufacturer or carrier, as patches for chipset-level flaws are usually delivered through the phone's normal software update mechanism.

For organizations that manage a fleet of Android devices or rely on smartphones to access business systems, proactive monitoring and update enforcement are essential. AEU-I, a security-first IT and infrastructure consulting service from AEU Group, can help businesses assess device security policies, ensure that critical patches are applied promptly, and reduce the risk of mobile-originated compromises reaching their hosting or cloud environments. Keeping devices patched and applying least-privilege access are core steps that complement such professional oversight.

How to Protect Yourself

  1. Turn on automatic security updates on your phone and install any update as soon as it appears, because updates fix security holes like this one.
  2. Do not answer video calls from unknown numbers until your phone has been updated with the latest security patch.
  3. If you use your phone for work or to log into website admin areas, use a different, fully updated device or a computer with security software.
  4. Check your phone manufacturer's support website for any security notice about Unisoc processors and follow their advice.
  5. Tell your family or coworkers who use budget Android phones to update their devices and be careful with unexpected video calls.

Related AEU services

  • AEU-I IT and security consulting