Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical UNISOC T612 Modem Flaw Enables Remote Code Execution via Cellular Calls

A significant security vulnerability has been identified in UNISOC modem firmware, enabling attackers to remotely execute arbitrary code over cellular networks.

A significant security vulnerability has been identified in UNISOC modem firmware, enabling attackers to remotely execute arbitrary code over cellular networks.

UNISOC manufactures chipsets used in mobile devices from brands such as Motorola, Samsung, Vivo, and Realme. This vulnerability potentially affects millions of devices.

The vulnerability enables an attacker to compromise a device by initiating a cellular call. By sending specially crafted Session Description Protocol (SDP) messages during Session Initiation Protocol (SIP) signaling, an attacker can trigger memory corruption in the modem of the target device.

This issue is classified as an Uncontrolled Recursion problem, tracked as CWE-674 in the Common Weakness Enumeration system. The vulnerability arises from improper handling of specific message attributes by the modem without adequate validation.

The vulnerability is traced to the _SDPDEC_AcapDecoder function, which handles the acap attribute in SDP messages. The unsafe parsing logic allows the decoder function to call itself recursively without limits.

UNISOC manufactures chipsets used in mobile devices from brands such as Motorola, Samsung, Vivo, and Realme.
Kyle Mercer · Thehackingpost

An attacker can exploit this by sending input with multiple acap attributes on a single line, causing the modem to overflow the SIP task's stack. This results in memory collision with the sblock_0_2 task.

For successful exploitation, the sblock_0_2 task must be active, typically during high-bandwidth operations such as video calls. Additionally, a crypto attribute allows the adversary to overwrite critical function pointers and achieve remote code execution.

The attack was demonstrated by security researcher 0x50594d and SSD Secure Disclosure in a controlled environment using a Dockerized Open5GS deployment and a LimeSDR antenna for 4G communication with a target smartphone.

Advertisement

The exploit affects several UNISOC chipsets, including T612, T616, T606, and T7250 models. Testing confirmed the vulnerability on a Realme C33 smartphone with the July 2025 Android security update.

Attempts to contact UNISOC for a patch have been unsuccessful, leaving devices using these modems vulnerable to unauthorized remote code execution.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories