SECURITY·중요도 9·2026. 08. 17.·The Hacker News
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
── KO ──────────────────
Unisoc VoLTE 취약점을 통해 안드로이드 커널에 완전 접근할 수 있는 공격 기법이 공개됐다.
SSD Secure Disclosure의 보안 연구자들이 Unisoc 모뎀 펌웨어에서 VoLTE 영상 통화를 이용한 2단계 익스플로잇 체인을 발표했다. 이 체인은 안드로이드 커널에 대한 완전 접근을 가능하게 하며, 칩셋 제조사로부터 수정사항은 없다. 2026년 3월에 공개된 원격 코드 실행 취약점의 두 번째 단계로, 보안에 중대한 위협을 초래하고 있다.
── EN ──────────────────
Unisoc VoLTE vulnerability allows full Android kernel access through an exploit chain.
Security researchers at SSD Secure Disclosure have revealed a two-stage exploit chain that enables full Android kernel access on devices using Unisoc modem firmware via a VoLTE video call. This vulnerability presents a significant risk, as there is no fix provided by the chipset manufacturer. The second stage of this chain follows a previously disclosed remote code execution vulnerability from March 2026.