Cybersecurity researcher operating under the pseudonym 0x50594d demonstrated a vulnerability that allows full root control of a smartphone to be obtained as a result of an ordinary video call. According to their findings, the root of the problem lies in the modem firmware of several Unisoc processors, which are widely used in budget devices from Xiaomi, Motorola, and Realme. In the event of a successful attack, the attacker gains the ability to modify the Android operating system, and thus — effectively full control over the device. Reports detailing the PoC emerged against the backdrop of the chip manufacturer itself, Unisoc, not having responded to the researcher's disclosure at the time of publication.
How the attack works
According to the researcher's description, the issue is characterized as an "exploitable vulnerability related to improper isolation of shared resources in a system on a chip." In the Unisoc modem firmware, they say, a critical flaw was found that allows arbitrary code execution with kernel privileges from the modem context. Once the ability to execute code on the modem is obtained, the attacker, in 0x50594d's assessment, is able to read and write data across the entire memory space by disabling protection in the first region of the memory protection block. It is precisely this mechanism, the researcher claims, that makes a single video call sufficient to escalate to root access.
Which devices are at risk
The flaw was found in the modem firmware of the Unisoc T612, T616, T606, and T7250 chips, so formally all devices built on these processors are at risk. The proof of concept was carried out on specific models: the Realme C33, the Xiaomi Redmi A5 with the 2026-01-01 security update, and the Motorola E13 with the 2025-02-01 update. In addition, all three devices had the July 2025 Android security update installed, which, in the researcher's logic, indicates that the vulnerability had not been patched by the latest updates at the time of testing.
Technical essence and limitations of the verification
It is important to emphasize two significant caveats that the source itself provides alongside the demonstration. First, the proof of concept was performed under laboratory conditions, not in real carrier networks, so the transfer of the attack to a mass user under normal network conditions has not been confirmed. Second, on the test devices root access had already been obtained before the attack began, which means: in a typical user configuration without prior rooting, the consequences of the exploit may turn out to be significantly less critical than in the laboratory scenario.
Contradictory data
There is clear tension between two assessments here. On the one hand, the researcher calls the flaw "critical" and highlights the possibility of arbitrary code execution with kernel privileges and full control over memory — this is an argument in favor of high danger. On the other hand, the same source notes that the PoC was built in a laboratory, not in carrier networks, and that the devices initially had root, which means "the attack may have no real consequences." Thus, the "critical vulnerability with root via video call" version and the "limited laboratory PoC without proven mass impact" version coexist in a single article, and the final severity assessment depends on whether the attack can be reproduced under real network conditions on non-rooted devices.
Unisoc's position and what users should do
At the time of preparing this material, Unisoc had not responded to the researcher's message, so independent confirmation or refutation of the vulnerability by the manufacturer is still absent. Under these conditions, a reasonable line of action for owners of budget smartphones on the T612, T616, T606, and T7250 chips is to keep the firmware and Android security updates up to date, not to accept video calls from unknown senders in suspicious scenarios, and to monitor official patches from Unisoc and device vendors. Until an official comment from the manufacturer and independent reproductions in real networks appear, the level of risk should be considered confirmed with caveats.