Tech
🇦🇫 AfghanistanUnisoc Modem Software Can Give Attackers Access to the Android Operating System's Kernel Through Volte Video

The attack requires a special 4G network and the target to answer an incoming video call, and no patch is currently available. The vulnerability creates a two-stage attack on Android devices using Unisoc modem software. The first stage exploits a video call flaw to execute remote code on the modem.
In the second stage, the attacker can access the memory where the Android kernel resides. For this, the attacker must control the 4G network and the target must accept the VoLTE video call. The root of the problem lies in the modem and processor sharing the same memory space.
Researchers changed ARM security settings on the modem, making the entire 32-bit address space readable, writable, and executable. This allowed the modem to interfere with memory pages containing the Android kernel. The team confirmed the attack code worked with outputs.
The flaw affects at least three Unisoc chipsets, including the T606, T612, and T7250. Researchers verified the issue on Motorola E13 and Xiaomi Redmi A5 devices. The Realme C33 also uses one of the affected chips. Android's August security update does not cover this vulnerability, and Unisoc has not shared a fix.
SSD said it tried to reach the company but received no response. Users must now wait for software updates from device manufacturers.
Source: CNN Türk Teknoloji
Most read in this category
Loading article…