A video call to a cheap handset now reaches the Android kernel, and nobody is patching it
SSD Secure Disclosure published the second half of an exploit chain against Unisoc modem firmware on 17 August. The precondition — the attacker must run the cellular network — describes a state, not a criminal.
SSD Secure Disclosure published an advisory on 17 August describing a two-stage chain that achieves full Android kernel access on devices running Unisoc modem firmware, delivered through a VoLTE video call. It completes work the researchers began in March 2026, when they disclosed remote code execution in the same firmware via a malformed SIP video call. The chain has two demanding preconditions: the attacker must control a private 4G cellular network, and the victim must answer the incoming call. There is no fix from the chipset maker. “We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response,” the advisory states. The Hacker News carried the disclosure on 17–18 August. No exploitation in the wild has been reported. This is a capability, not an incident.
The precondition is the point. Controlling a private 4G network is the working profile of an operator running a cell-site simulator or a compliant carrier environment, not of a ransomware crew. It sits alongside Citizen Lab’s April report, “Bad Connection,” by Gary Miller and Swantje Lange, which documented two telecom surveillance campaigns combining 3G and 4G signalling protocols with direct device exploitation over SMS — including a message carrying hidden SIM card commands that extracted location and turned the handset into a covert tracking beacon — and customised tooling to spoof operator identities and steer traffic through chosen interconnect paths to mask attribution. That report has been recirculating this month reframed by advocacy accounts as a story about Israeli-linked infrastructure. Israel is one of five jurisdictions Citizen Lab names, alongside the UK, China, Thailand and Sweden.
Unisoc basebands are common in low- and mid-tier handsets across the Middle East, Africa and South Asia, which is why the disclosure belongs on this desk — but The Files has not verified Unisoc’s share of any Gulf, Levantine or Sahel market and will not assert regional exposure without it. Two adjacent threads remain open. SecurityWeek’s index carries an undated line describing a “novel private APN pivot” used to sabotage a second Polish energy facility, technically close to the same access model, which The Files has not read or dated. And the July 22 update to the CISA/FBI/EPA advisory AA26-097A on “Iran-affiliated” actors — four weeks old, though circulating this week as current — documents access to industrial controllers over internet-exposed OT ports 44818, 2222, 102 and 502 and via modems on SSH port 22. Network-level access, in each case, is the whole game.
Assessment: Device exploitation is drifting from the endpoint back into the network, and that shifts who can plausibly be behind an intrusion. A bug requiring the attacker to own the radio access network is not a bug most buyers can use; it is one a government or a lawful-intercept intermediary can. The corollary is that unpatched, low-cost basebands function as a policy question about handset markets rather than a vendor-response question — Unisoc has not answered SSD at all. Two habits to hold: do not upgrade a capability into an incident because it is alarming, and note that recirculated reports acquire sharper politics than their own findings support, in both directions.