A Critical Unisoc Chip Flaw Leaves Budget Android Phones Exposed to Video Call Exploits
Key points
- Security researchers have demonstrated a critical vulnerability in modem firmware across several Unisoc system-on-chip models, including the T612, T616, T606, and T7250.
- The exploit can be triggered using any standard smartphone to place a video call, delivering malicious code directly through call setup messages.
- Affected processors are commonly found in budget-friendly mobile devices produced by major brands like Xiaomi, Motorola, and Realme.
- While the proof-of-concept requires specific conditions such as rooted test devices and a closed network, the chip manufacturer has reportedly failed to respond to the disclosure.
Anatomy of the Exploit
A severe security flaw rooted in the modem firmware of select Unisoc processor chips has raised fresh concerns across the mobile landscape 1. Discovered by a researcher operating under the alias 0x50594d, the vulnerability stems from improper resource isolation within the system-on-chip architecture. By sending specially crafted malicious code hidden inside call setup messages during a video call, an attacker can achieve arbitrary code execution with kernel privileges originating from the modem context. This breach allows malicious actors to dismantle memory protections entirely, granting them the capability to read and write across the device’s entire memory space and ultimately secure full root access to the targeted handset.
Impacted Devices and Hardware
Although lesser-known than major semiconductor competitors like Qualcomm, MediaTek, or Apple, Unisoc maintains a substantial global footprint in the budget electronics market. Its processors power an array of affordable mobile and Internet of Things products distributed by prominent manufacturers such as Samsung, Motorola, Xiaomi, and Realme 1. The newly documented firmware flaw specifically affects four distinct Unisoc system-on-chip models: the T612, T616, T606, and T7250. During initial testing documented on the SSD Secure Disclosure platform, researchers successfully demonstrated the exploit against several concrete models, including the Realme C33, the Xiaomi Redmi A5, and the Motorola E13 1.
Context and Real-World Risk
Despite the alarming capability of granting total handset control, cybersecurity experts emphasize that executing the attack in the wild presents significant hurdles 1. The proof-of-concept testing was performed under tightly controlled laboratory environments, utilizing a closed Voice over LTE network rather than a live carrier network 1. Furthermore, the target devices used in the demonstration were pre-rooted – a modification that inherently compromises standard operating system sandboxing and invites malware risks – and were operating on older software patches 1. Compounding the situation, the manufacturer has reportedly remained unresponsive to the initial security disclosures, leaving device owners and security analysts waiting for an official patch or acknowledgment 1.
Companies mentioned: Xiaomi • Qualcomm (QCOM $160.74 ▼0.7%) • Apple (AAPL $311.30 ▼1.7%) • Samsung
Primary sources
Android users beware — if you own one of these budget smartphones, your device could be hacked with a simple video call (techradar.com) – This source details a critical firmware vulnerability in Unisoc system-on-chips used across various budget Android smartphones that allows attackers to gain root access via video call setup messages.

Powered by News Ranker