Phones Powered by Unisoc SoCs Vulnerable to Remote Hacker Attacks: Check Point Research

The vulnerability exists within the Unisoc modem powering 11 percent of smartphones, Check Point Research said.

Advertisement
By Jagmeet Singh | Updated: 2 June 2022 19:16 IST
Highlights
  • Check Point Research disclosed its findings to Unisoc in May
  • It could allow attackers to block radio communication on devices
  • Unisoc has issued a patch for the critical vulnerability in question

The issue was identified using the Moto G20, though it exists on other phones as well

Photo Credit: Motorola

Mobile phones powered by Unisoc chips are found to be vulnerable to an issue that could allow attackers to remotely block communication. Cybersecurity analysis firm Check Point Research on Thursday announced that it identified a vulnerability in the Unisoc modem that could impact communication. The issue exists in the modem firmware and affects 4G and 5G Unisoc chipsets, according to the firm. Unisoc acknowledged the vulnerability and considered it of critical nature, giving a 9.4 score out of 10.

Check Point Research said in its report that the critical vulnerability, which is tracked as CVE-2022-20210, was discovered while scanning Non-Access Stratum (NAS) message handlers. Using a malformed packet, the issue could allow a hacker or a military unit to disrupt the radio communication of a device.

Advertisement

The researcher at Check Point Research was able to detect the vulnerability on the Unisoc T700 chip-based Motorola Moto G20 with the Android January 2022 security patch. However, the issue is not limited to a particular Unisoc SoC model or a specific phone.

"We found a vulnerability in the Unisoc modem built in 11 percent of smartphones," said Slava Makkaveev, Reverse Engineering and Security Research attorney at Check Point Software, in a prepared statement. "An attacker could have used a radio station to send a malformed packet that would reset the modem, depriving the user of the possibility of communication. Left unpatched, cellular communication can be blocked by an attacker."

Advertisement

Makkaveev added that the vulnerability was found in the Unisoc modem firmware and not in the Android operating system itself.

Check Point Research disclosed its findings to Unisoc in May. The Shanghai-based chipmaker acknowledged the vulnerability upon the receipt of disclosure and issued a patch.

Advertisement

However, the fix has not yet reached users. Google said that it will be publishing the given patch in the upcoming Android Security bulletin, the research firm noted.

Check Point Research urges users to always update their mobile phones to the latest software version available.

Advertisement

Unisoc, previously known as Spreadtrum, has been getting bigger in the market of smartphone chipmakers for the last few months.

According to a recent report by market research firm Counterpoint, the share of Unisoc grew to 47 percent in the first quarter of the year from 20 percent in the same quarter last year. It also gave a tough fight to MediaTek that struggled with supply constraints for 4G chips.

Companies including Samsung, Motorola, and Realme are using Unisoc SoCs in their budget phones.


Should you buy a 4G or 5G budget phone? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Marvel's Wolverine Gets Gameplay Trailer at State of Play, Pre-Orders Go Live
  2. Instagram Alerting Users After Meta AI Exploit Enabled Account Takeovers
  3. Apple Reportedly Agrees to Hand Over India-Specific Financial Data to CCI
  4. RTX Spark-Powered Laptops Could Cost a Lot More Than Regular AI PCs
  5. Lumio Launches 55-Inch Variants of Vision 9 (2026), Vision 7 (2026) in India
  6. Samsung Galaxy A27 Reportedly Bags US FCC Certification, May Launch Soon
  7. Xiaomi 18, 18 Pro and 18 Pro Max Specifications Leaked Ahead of Debut
  8. Realme P4R 5G India Launch Date, Design and Key Specifications Revealed
  1. Dashlane Password Manager Reveals Hackers Stole Some Encrypted Vaults Using Brute-Force Attacks
  2. Apple Doubles MacBook Neo Output as Budget Laptop Gains Popularity, Analyst Says
  3. Apple Reportedly Agrees to Hand Over India-Specific Financial Data to CCI in Years-Long Antitrust Case
  4. Apple Confirms macOS 27 Will End Support for Intel Macs Ahead of WWDC 2026
  5. Instagram Begins Warning Users Affected by Meta AI Hack That Enabled Account Takeovers
  6. UK's FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsor Risks
  7. Vivo X500 Pro Max Display and Battery Details Surface Online in Early Leak; Largest Model Said to Feature 6.85-Inch Screen
  8. Google Introduces Fake Call Detection for Android Phones to Curb Call Spoofing Attacks
  9. Google Rolls Out Gemini Thinking Levels Across Platforms With 'Extended' Thinking Mode for All Users
  10. Samsung Galaxy A27 Reportedly Bags US FCC Certification Ahead of Anticipated Launch
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.