A Video Call Can Now Hand Attackers the Keys to Your Android Phone

Researchers say a two-stage exploit against Unisoc modem chips turns a VoLTE video call into full kernel access, and there's no patch.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A smartphone displaying an active video call on its screen, while security analysis diagrams on a laptop behind it reveal the multi-stage exploit path to kernel
Share

Key points

  • Researchers at SSD Secure Disclosure published a working attack on August 17, 2026 that gives full control of an Android phone through a video call.
  • The attack targets phones using Unisoc modem chips, parts common in budget Android handsets worldwide.
  • The chain has two stages: a March 2026 flaw in the modem, and a new August 2026 flaw that escalates from the modem into the phone's main operating system.
  • Unisoc has not released a fix, and the attack needs no taps or clicks from the victim.
  • Owners of affected phones can't patch this themselves; carriers and phone makers must wait for Unisoc to respond first.

A researcher can now call your phone over 4G video and walk out with everything on it.

That's the practical upshot of an advisory published by SSD Secure Disclosure on August 17, 2026, picked up by The Hacker News. It describes a two-step attack against phones using Unisoc modem chips, the radio processor that handles calls and mobile data.

Step one came in March. Step two, published this month, is the nastier half: it lets an attacker escape the modem and take control of the Android kernel, the core of the phone's operating system that has authority over everything else.

Own the kernel and you own the phone. Photos, messages, banking apps, microphone, camera.

How does the attack actually work?

An attacker places a VoLTE video call to the target. VoLTE, short for Voice over LTE, is the standard way modern phones carry calls over 4G data rather than the old voice network.

The malformed call data hits the Unisoc modem and triggers the first bug, the March 2026 remote code execution flaw, giving the attacker a foothold inside the modem chip itself. The August flaw is the bridge: code running on the modem reaches across into Android's kernel and takes over. No app install, no link, no user tap. The phone just needs to be reachable on the mobile network.

We reported a kernel-level flaw in Samsung's KNOX framework back in June, in "Samsung KNOX Use-After-Free Bug Sat in Galaxy Devices for Eight Years Before Patch". What's different here is the attack vector: that one needed the device in hand; this one needs only your phone number.

Which phones are at risk?

Any Android phone using an affected Unisoc modem. Unisoc chips appear heavily in budget and mid-range devices sold across Asia, Africa, Latin America and Europe. Brands including Motorola and Nokia have shipped Unisoc-based models in recent years, and Samsung's lower-end A-series has used the chips in certain markets.

SSD says Unisoc was notified and hasn't shipped a fix. Even if a phone maker wanted to patch this tomorrow, the fix must come from Unisoc first, flow through the phone brand, then through the carrier, then reach the handset.

Detail What we know
First flaw disclosed March 2026, remote code execution in Unisoc modem
Second flaw disclosed August 17, 2026, modem-to-kernel escalation
Attack vector Inbound VoLTE video call
User interaction needed None
Vendor fix available No

Should ordinary phone owners be worried?

Attacks like this are expensive to build and tend to get aimed at specific people: journalists, activists, executives, government targets. Random users aren't the priority.

If you're in a higher-risk group and you own a Unisoc-based phone, the honest advice is to consider a different device until a firmware update arrives. Turning off VoLTE where your carrier allows it cuts the attack path, at the cost of call quality falling back to older voice standards.

For everyone else: keep automatic updates on and check for a system update once Unisoc and your phone maker respond. This is the kind of flaw that gets quietly patched in a monthly Android security bulletin.

MFA wouldn't have helped here. This attack sits below the apps where authentication lives. When the kernel is owned, the login prompt is theatre.

© 2026 Threat Vectr