# Answering Your Phone Is Now an Attack Vector: The Unisoc Modem Exploit Chain


There's a particular kind of dread reserved for vulnerabilities where the victim's only mistake was picking up the phone. Researchers have now documented exactly that scenario in Unisoc modems — a two-flaw chain that hands an attacker full control of an Android device the moment the call connects.


No malicious app. No phishing link. Just a ringing phone and a user who answered.


## How the Chain Works


The exploit combines two distinct vulnerabilities in Unisoc's modem firmware, which handles the low-level radio communication layer on affected Android devices. This is the baseband — the software stack that manages cellular protocols, sits below Android's application layer, and runs with hardware-level privilege.


The attack flow, as researchers describe it: an attacker delivers a payload and waits. When the victim answers their call, the second flaw activates. The combination achieves remote code execution with the kind of access that makes OS-level security controls largely irrelevant.


The significance of chaining matters here. Neither flaw in isolation necessarily produces a critical outcome. Separately, they might be annoying footnotes in a CVE database. Together, they become a pre-interaction remote compromise. This is the math of modern exploit development — vendors patch individual bugs while researchers are already hunting for the combination that makes those individual bugs irrelevant.


The attack surface is the telephony stack itself. You cannot opt out of it. You cannot turn off the feature that's being abused without turning off your phone.


## Who Makes Unisoc Chips, and Who Uses Them


Unisoc — formerly Spreadtrum Communications — is the third-largest mobile chipmaker in the world by volume, behind Qualcomm and MediaTek. That ranking is important context. They don't power flagships. They power the sub-$150 Android market: entry-level smartphones sold across sub-Saharan Africa, Southeast Asia, South Asia, and Latin America.


This isn't a niche product. Unisoc ships hundreds of millions of chips annually. Devices carrying their modems are often the *only* smartphone a household owns, used for mobile banking, government services, healthcare apps, and communication in regions where those functions have no offline alternative.


The populations most exposed to this vulnerability tend to have the least access to timely security patches — because manufacturers of budget devices have historically poor track records on firmware updates, and because the Android update ecosystem below the major OEMs is fragmented to the point of dysfunction.


Check Point Research disclosed a critical Unisoc modem vulnerability in 2022 (CVE-2022-20210) that could allow remote denial-of-service or code execution via crafted LTE packets — no user interaction required at all. That flaw stayed unpatched on millions of devices long after public disclosure because there was no economic incentive for manufacturers to issue firmware updates to devices they'd already sold in low-margin markets.


This new chain lands in that same ecosystem.


## The Baseband Problem Nobody Wants to Solve


Baseband security has been a known gap for over a decade. Google Project Zero has documented attack surfaces in Qualcomm, Samsung Exynos, and MediaTek modems. The common thread: baseband processors run proprietary RTOS firmware, often with minimal exploit mitigations, with privileged access to SMS, call audio, location data, and sometimes main processor memory.


The security research community refers to this as the "modem problem" — a hardware layer where the chip vendor controls the code, the OEM ships the device, and the carrier often controls the update path. Three separate parties, none of whom have clear accountability for the security lifecycle.


When a vulnerability lands in this stack, the remediation path is complicated even when vendors cooperate fully. Unisoc would need to issue a firmware patch. OEMs would need to receive it, integrate it, test it, and push it. Carriers may need to approve it. For a $120 device sold eighteen months ago in a market without mandatory update requirements, this chain often simply doesn't complete.


The result is a vulnerability that researchers disclose, a CVE that gets filed, and millions of devices that never receive the fix.


## What Defenders Can Actually Do


For enterprise security teams, the immediate question is device fleet visibility. Unisoc-powered devices are unlikely to appear in most corporate MDM inventories in North America or Europe, but the gap matters for organizations with global operations, remote workforces, or BYOD policies in emerging markets.


For individuals: this is genuinely difficult. There's no configuration change that closes a baseband vulnerability. The mitigations that exist are indirect — using Wi-Fi calling where available (which routes calls over the internet stack and may not touch the vulnerable modem path), keeping devices updated on whatever firmware version the manufacturer provides, and treating unsolicited incoming calls from unknown numbers with appropriate skepticism.


For policy: the more structural answer is mandatory update timelines for devices sold in major markets, which the EU's Cyber Resilience Act is beginning to address and the US has yet to meaningfully legislate.


---


## HackWire Analysis


The Unisoc story is a useful stress test for how the security industry thinks about vulnerability disclosure and responsible coverage. Coverage of baseband exploits tends to spike around flagship device disclosures — Samsung Exynos bugs get breathless headlines, Qualcomm Snapdragon flaws get congressional attention. Unisoc disclosures largely pass without notice.


That asymmetry isn't just a media bias problem. It reflects a deeper structural truth: the security research ecosystem — bug bounty programs, vendor security teams, academic research grants — is oriented toward platforms with large, affluent user bases. The devices most likely to go unpatched, used by populations with the fewest alternatives, attract the least attention and the fewest resources.


What this exploit chain actually demonstrates isn't that Unisoc is uniquely careless. It's that the modem attack surface is broadly underinvested across the industry, and that the devices where underinvestment has the most consequence are the ones nobody is paying to secure. This is a market failure, not a technical accident.


The "answer your phone" attack model is also worth watching as a trend. As zero-click iMessage and WhatsApp exploits have grown more expensive and more closely monitored, the telephony stack at the baseband level represents an avenue that's comparatively underresearched, underpatched, and — critically — not covered by the same level of scrutiny that OS-layer vulnerabilities receive.


Defenders running global operations should be mapping their Unisoc exposure now. The patch timeline, based on prior incidents, won't be fast.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)