Security researchers have discovered an exploit chain affecting Unisoc modems that allows attackers to seize control of Android devices through a simple phone call. The attack leverages two separate vulnerabilities in Unisoc's modem firmware, a chipset used in millions of budget and mid-range Android phones worldwide.

The exploit works by combining memory corruption flaws in the Unisoc modem stack. When a victim answers an incoming call from an attacker, malicious code embedded in the call payload executes with modem-level privileges. This grants attackers direct access to the device's baseband processor, bypassing Android's application sandbox entirely.

The technique does not require user interaction beyond accepting the call. No clicking malicious links, installing apps, or granting permissions necessary. The victim simply answers what appears to be a normal incoming call.

Unisoc modems power entry-level and mid-range Android handsets from multiple manufacturers. The chipsets appear in devices from brands including Samsung, Motorola, and others selling in emerging markets where budget phones dominate. The exact number of affected devices remains unclear, but estimates suggest tens of millions globally.

Once compromised, attackers gain baseband access. This permits surveillance of all communications, interception of SMS messages, location tracking, and installation of persistent backdoors. The compromise occurs at a layer below Android's security model, making detection and removal extremely difficult for users.

Researchers disclosed the vulnerability details responsibly to Unisoc and affected device manufacturers before public disclosure. Unisoc has released patches addressing the flaws. However, patch distribution through carriers and manufacturers moves slowly for budget devices, meaning millions of vulnerable phones likely remain in active use.

Users with Unisoc-based devices should check for security updates from their carrier or manufacturer. Device manufacturers should expedite rollout of patched firmware. The vulnerability underscores ongoing risks in the