Jessica Entwistle
August 18 2026
Infosecurity Magazine and Dark Reading report that security researchers have discovered a vulnerability in UNISOC modems that could allow an attacker to achieve kernel-level code execution on Android devices by exploiting a flaw during video call handling. The vulnerability requires the attacker to deliver a specially crafted payload and persuade the victim to answer a video call. UNISOC is a Chinese semiconductor company whose modems are used in millions of Android devices, particularly in budget and mid-range smartphones sold globally. The flaw affects the modem firmware, which operates at a privileged level within the device and is responsible for handling cellular communications. Successful exploitation could allow an attacker to gain deep access to the device, potentially enabling surveillance, data theft or further compromise of connected networks.
For UK organisations that issue mobile devices to staff, or that allow personal devices to connect to corporate networks and services, this vulnerability highlights the importance of understanding the supply chain and component-level security of the devices being used. Modem vulnerabilities are particularly concerning because they operate below the main operating system and can be difficult to detect or remediate. Devices using affected UNISOC modems may not receive timely security updates, particularly if they are older models or from manufacturers with poor patch management track records. The operational risk is that compromised devices could be used to access corporate email, cloud services, VPNs or internal applications, potentially providing attackers with a foothold into the wider organisation. The social engineering element of the attack, requiring the victim to answer a video call, is a reminder that technical vulnerabilities are often exploited in combination with human interaction. Organisations that rely on mobile devices for remote working, field operations or customer-facing roles need to consider how device security fits into their broader risk management and incident response planning.
Organisations should review whether mobile device management policies include requirements for devices to receive regular security updates, whether older or unsupported devices are being phased out, and whether network access controls limit what compromised devices could reach. It is also worth checking whether staff are aware of the risks of answering unexpected video calls from unknown numbers, and whether there are clear processes for reporting suspicious activity on corporate or personal devices used for work. Organisations should also review whether mobile device procurement policies prioritise devices from manufacturers with strong security track records and timely patch management, and whether there is visibility into the hardware components and firmware used in devices connecting to corporate networks. Finally, it is worth ensuring that incident response plans include clear processes for isolating and investigating compromised mobile devices, and that security operations teams have the tools and training to detect unusual activity originating from mobile endpoints.
Source: Infosecurity Magazine