Executive brief
A vulnerability exists in the IP Multimedia Subsystem (IMS) of several Unisoc chipsets, which are components responsible for handling voice and data services on mobile devices. An attacker could remotely exploit this flaw to crash the device's modem functionality, leading to a total loss of cellular connectivity and a denial of service. This attack can be carried out over the network without any user interaction or special permissions.
Technical details
A vulnerability classified as a stack-based buffer overflow (CWE-121) and out-of-bounds read exists in the IMS (IP Multimedia Subsystem) component of the Unisoc modem firmware. The root cause is a missing bounds check when processing incoming network data. A remote, unauthenticated attacker can exploit this over the network (AV:N) with low complexity (AC:L) and no user interaction (UI:N). Successful exploitation results in a denial of service (DoS) of the modem functionality. The issue affects multiple chipsets including SC7731E, T610, and T8300 running Android versions 13 through 16.
Affected products
- Unisoc SC7731E Android 13, 14, 15, 16
- Unisoc SC9832E Android 13, 14, 15, 16
- Unisoc SC9863A Android 13, 14, 15, 16
- Unisoc T310 Android 13, 14, 15, 16
- Unisoc T610 Android 13, 14, 15, 16
- Unisoc T618 Android 13, 14, 15, 16
- Unisoc T7200 Android 13, 14, 15, 16
- Unisoc T7225 Android 13, 14, 15, 16
- Unisoc T7250 Android 13, 14, 15, 16
- Unisoc T7255 Android 13, 14, 15, 16
- Unisoc T7280 Android 13, 14, 15, 16
- Unisoc T7300 Android 13, 14, 15, 16
- Unisoc T8100 Android 13, 14, 15, 16
- Unisoc T9100 Android 13, 14, 15, 16
- Unisoc T8200 Android 13, 14, 15, 16
- Unisoc T8300 Android 13, 14, 15, 16
Timeline
- 2026-07-03: advisory
- 2026-07-03: disclosed