Critical Unisoc Chip Vulnerability Exposes Budget Android Devices to Remote Exploits
A flaw in modem firmware across multiple Unisoc processors could allow arbitrary code execution through video calls, though real-world risk remains constrained.

A newly disclosed security vulnerability in modem firmware powering several Unisoc microprocessors could allow attackers to gain root access to target devices during a video call, as first reported by TechRadar Pro. The flaw affects budget Android handsets manufactured by major hardware brands, highlighting potential hardware-level security risks in low-cost mobile chipsets.
According to technical documentation published by security platform SSD Secure Disclosure, the vulnerability stems from an improper isolation of shared resources within Unisoc modem firmware. The issue impacts four specific System-on-a-Chip (SoC) designs: the Unisoc T612, T616, T606, and T7250.
The research was conducted by an independent security researcher operating under the pseudonym 0x50594d. The disclosure detailed how an attacker capable of executing arbitrary code within the modem context can disable system protections on the initial Memory Protection Unit (MPU) region, designated as region ID 0. Disabling this boundary grants complete read and write access across the handset's total memory space with kernel-level privileges.
Proof-of-concept testing was performed on specific budget hardware models, including the Xiaomi Redmi A5 carrying a security patch level of 2026-01-01 and the Motorola E13 running a security patch level of 2025-02-01. Both test units had received July 2025 Android security updates. The affected chipsets are also deployed across devices built by Realme and integrated into various smart home and Internet of Things (IoT) products.
Unisoc remains a significant global supplier in the semiconductor market, currently ranking fourth in mobile processor market share behind MediaTek, Qualcomm, and Apple. The Shanghai-headquartered fabless chipmaker routinely supplies processors for entry-level devices produced by prominent global original equipment manufacturers, including Samsung and Motorola.
Despite the critical severity of the theoretical exploit, the researchers noted that the vulnerability was demonstrated under constrained experimental conditions. The handsets utilized during testing were rooted prior to the exploit attempt—a state that modifies core system permissions and is absent on standard consumer devices. Furthermore, the test payload was delivered across a closed VoLTE network rather than a commercial mobile carrier network, leaving the real-world impact on unmodified consumer hardware unverified.
At the time of disclosure, Unisoc had not provided a response or published a security advisory addressing the reported modem firmware flaw, leaving the prospective timeline for carrier and OEM firmware patches undetermined.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



