Check Point Research unveils vulnerability within UNISOC baseband chipset

Issue 3 2022 News & Events

UNISOC produces budget chipsets that power 2/3/4/5G devices ranging from smartphones to smart TVs. UNISOC is extremely popular in Africa and Asia due to its low-end prices. By the end of 2021, UNISOC was reported to be the fourth largest smartphone chip manufacturer globally (following MediaTek, Qualcomm and Apple), with an 11% global market share.

Despite the fact that UNISOC has been on the market for a long time, the UNISOC chip firmware, including the radio modem (AKA baseband), has not been studied extensively. There are no references for any UNISOC baseband vulnerabilities on the Internet to date, and this served as primary motivation for Check Point researchers.

The smartphone modem is a prime target for hackers as it can be potentially reached remotely through SMS or radio packets. Check Point Research discovered several vulnerabilities that can jeopardise the modems and other chip-related weaknesses that can put Android mobile users at risk.

Exploiting this vulnerability can be used to disrupt the device’s radio communication through a malformed packet. An attacker or even a military unit can use such a vulnerability to neutralise communications on the attacked devices.

Check Point Research reached out to the UNISOC teams in May 2022 and disclosed these findings. UNISOC acknowledged the findings and gave the vulnerability a 9.4 scoring (critical) and patched it. Google has said it will be publishing the patch in the upcoming Android security bulletin.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Pentagon appointed as Milestone distributor
Elvey Security Technologies News & Events Surveillance
Milestone Systems appointed Pentagon Distribution (an Elvey Group company within the Hudaco Group of Companies) as a distributor. XProtect’s open architecture means no lock-in and the ability to customise the connected video solution that will accomplish the job.

Read more...
Re-introduction of the booking system
PSiRA (Private Security Ind. Regulatory Authority) News & Events
[Sponsored] PSiRA is reintroducing the booking system for branch visits. Effective Monday, 4 December 2023, clients will be required to book a slot to visit any PSiRA branch.

Read more...
From the editor's desk: A sad but exciting goodbye
Technews Publishing News & Events
Welcome to the final monthly issue of SMART Security Solutions. This is the last issue of the year and the last monthly issue we will print. The SMART Security Solutions team wishes all our readers and advertisers a relaxing festive season and a peaceful and prosperous 2024.

Read more...
Regal celebrates successful golf day
Regal Distributors SA News & Events
Regal Distributors held its first official Regal Golf Day on 18 October at the Glendower Golf Course in Johannesburg. SMART Security Solutions was there on a hot summer’s day to meet many players and sponsors around the course.

Read more...
Gallagher Security releases Command Centre v9
Gallagher News & Events Access Control & Identity Management Integrated Solutions
Richer features, greater integrations, with the release of Gallagher Security’s Command Centre v9 security site management software designed to integrate seamlessly with various systems and hardware.

Read more...
Regal launches direct-to-branch WhatsApp communication
Regal Distributors SA News & Events
With a quick scan of a QR code and a few taps on your phone, installers, integrators, technicians or even end-users can chat directly with the team at their preferred Regal branch via WhatsApp

Read more...
FM Expo highlights industry trends and challenges
Securex South Africa News & Events Facilities & Building Management
Keeping tabs on what is happening within the building/facilities management arena can be frustrating, however, a quick way to find out what current trends, challenges, and solutions are available can be found at the Facilities Management Expo.

Read more...
South Africa shows a 1200% increase in deepfake fraud
News & Events Risk Management & Resilience
Sumsub released its third annual Identity Fraud Report of the year, analysing identity fraud across industries and regions based on millions of verification checks across 28 industries and over 2 million fraud cases.

Read more...
Projections for 2024’s Advanced Threats Landscape
News & Events Information Security
Kaspersky Global Research and Analysis Team (GReAT) experts offer insights and projections for 2024 in the Kaspersky Security Bulletin, with a focus on the evolution of Advanced Persistent Threats (APT).

Read more...
Helping South African university students and staff to stay safe
News & Events
Buzzer is a free mobile app that allows users to quickly and easily report incidents of crime, violence, or harassment to campus security and other relevant authorities.

Read more...