A single video call can hijack millions of budget Android phones right now

Started by Jedi Poppy, Today at 12:52 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: A single video call can hijack millions of budget Android phones right now   Views(Read 90 times)
Active members in this topic:
Jedi Poppy(1) Steve59(1) Rachel_29(1)

Jedi Poppy

Security researchers have publicly disclosed a serious flaw in modem firmware used across a wide range of budget Android phones, one severe enough that simply answering a video call can hand a remote attacker full root access to the device with no app install, no link click, and no interaction from the victim beyond picking up the call. An independent researcher going by the alias 0x50594d demonstrated the exploit by placing a video call to a target phone and taking it over in real time, confirming the attack worked against a Realme C33, a Xiaomi Redmi A5, and a Motorola E13 during testing.

The underlying problem sits in modem firmware shared across several Unisoc system on chip models, specifically the T612, T616, T606 and T7250, chips that power a large share of the entry level Android market. The attack works by sending malformed data through the call setup process itself, exploiting a bug in how the modem's VoLTE video call handling parses that data, before the exploit chain escalates from that initial foothold all the way up to full kernel level access on the device. Because the attack targets the baseband, the small dedicated processor that talks directly to the cellular network, rather than the Android operating system itself, none of the usual app based security protections on the phone ever get a chance to intervene.

What makes this particularly alarming is the disclosure timeline. According to reporting on the case, the flaw was first responsibly disclosed to Unisoc roughly five months before this public release, and the company never responded or shipped any fix during that entire window, prompting the researchers to eventually go public with the full technical details and no patch available. No CVE identifier has even been assigned to the vulnerability as of this reporting, which makes it considerably harder for security tools, IT departments, and ordinary users to track or search for whether their specific device model is affected.

The patch level confusion compounds the danger further. One of the test devices, the Xiaomi Redmi A5, was running an Android security patch dated January 2026, seven months old but still theoretically current by typical device support standards, and it remained fully vulnerable regardless. That is because Android security updates and modem firmware updates are handled entirely separately, meaning a phone that looks perfectly up to date at the operating system level can still be running modem firmware that has never received a single update since the device left the factory.

Unisoc holds roughly 14 percent of the global smartphone chip market as of the first half of 2026 according to Counterpoint Research, supplying chipsets used by brands including Honor, Realme, vivo, Samsung and Motorola across more than 140 countries, which gives some sense of just how many devices could plausibly be sitting exposed to this exact attack path right now with no fix in sight and no clear way for an average owner to check.


Steve59

The gap between Android security patches and modem firmware updates is the part of this story that should genuinely worry more people than it currently seems to. A phone showing a recent security patch date gives a completely false sense of safety if the actual attack surface being exploited lives entirely outside that update mechanism.

Rachel_29

Five months of silence from Unisoc before this went public is honestly damning on its own regardless of how technically severe the bug itself is. Responsible disclosure exists specifically to give vendors a real chance to fix things quietly, and ignoring that window entirely just forces researchers into exactly this kind of public pressure release.

Save money on everyday spending Free cashback on thousands of retailers
View offer