Executive brief
A vulnerability exists in the IP Multimedia Subsystem (IMS) of several Unisoc mobile chipsets, which are used to handle voice and data services on smartphones. An attacker could remotely crash the device's modem, leading to a total loss of cellular connectivity and emergency services. This attack can be carried out over the network without any user interaction or special permissions.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Modem IMS component of multiple Unisoc chipsets. The flaw allows a remote, unauthenticated attacker to send malformed packets over the network to trigger a system crash or a denial-of-service (DoS) condition on the modem. The vulnerability affects chipsets running Android versions 13 through 16. Successful exploitation results in the loss of cellular functionality, including voice calls and data, until the modem or device is reset. Unisoc has released a security bulletin detailing the affected chipsets, including the T-series and SC-series models.
Affected products
- Unisoc SC7731E Android 13, 14, 15, 16
- Unisoc SC9832E Android 13, 14, 15, 16
- Unisoc SC9863A Android 13, 14, 15, 16
- Unisoc T310 Android 13, 14, 15, 16
- Unisoc T610 Android 13, 14, 15, 16
- Unisoc T618 Android 13, 14, 15, 16
- Unisoc T7200 Android 13, 14, 15, 16
- Unisoc T7225 Android 13, 14, 15, 16
- Unisoc T7250 Android 13, 14, 15, 16
- Unisoc T7255 Android 13, 14, 15, 16
- Unisoc T7280 Android 13, 14, 15, 16
- Unisoc T7300 Android 13, 14, 15, 16
- Unisoc T8100 Android 13, 14, 15, 16
- Unisoc T9100 Android 13, 14, 15, 16
- Unisoc T8200 Android 13, 14, 15, 16
- Unisoc T8300 Android 13, 14, 15, 16
Timeline
- 2026-05-05: advisory: Initial advisory published by Unisoc
- 2026-05-06: disclosed: NVD publication date