See how unisoc compares to other vendors in security performance
1. Executive Summary
This report details a systemic security failure affecting millions of budget Android devices deployed across Latin America. The vulnerability is not a single software bug but a deliberate supply chain deception orchestrated by ODM Longcheer and SoC vendor Unisoc, facilitated by OEM Motorola.
The core issue involves a hardcoded fscrypt provisioning bypass triggered by LCD ID lcd\td4168 and key 56ef134d... that allows the distribution of fraudulent security updates. These updates spoof the security patch level claiming "April 2026" while running vulnerable binaries from "March 2026", masking critical flaws like CVE-2021-39658 ismsEx, CVE-2022-38694 BootROM, and exported backdoors in com.spreadtrum.sgps.
This architecture creates a permanent attack surface that facilitates active financial fraud PIX hijacking, surveillance, and enterprise network compromise in the Latin American region, where these devices dominate the market.
2. The Attack Chain: "Silent Rescue"
The risk is compounded by a chain of vulnerabilities that work in concert:
Hardware Root Unpatchable: CVE-2022-38694 in the Unisoc BootROM allows permanent bypass of Secure Boot via physical USB access. Public tools spd\dump exist. Remote Entry Network: CVE-2025-31718 Modem RCE allows remote code execution via rogue cell towers IMSI catchers, common in urban LATAM centers. Privilege Escalation Zero-Permission: CVE-2021-39658 ismsEx service allows any app to send SMS or modify system properties without permissions, bypassing Android 2FA. System Backdoors Exported Components: com.spreadtrum.sgps exposes location tracking and system controls via dialer codes \#\#2266#\#\. Payload Delivery Silent Installers: Pre-installed system apps com.dti.amx Digital Turbine and com.inmobi.installer hold INSTALL\PACKAGES, allowing silent installation of banking trojans e.g., PixRevolution without user consent. The Cover-Up FOTA Spoofing: The fscrypt bypass injects a fake ro.build.version.security\patch string, tricking users, banks, and MDM systems into believing the device is secure.
3. Critical Risk to Latin America LATAM
The impact on Latin America is disproportionate and severe due to market dynamics and reliance on mobile finance.
A. Market Dominance of Vulnerable Devices Ubiquity: Unisoc T606/T616 chipsets power the best-selling budget devices in the region Motorola Moto G04s, G24, Infinix, Tecno. Search results confirm Unisoc's aggressive expansion in LATAM, with over 100 5G devices deployed in the region by 2025. Demographic Impact: These devices are the primary computing tool for unbanked and underbanked populations who rely exclusively on smartphones for government aid, commerce, and banking.
B. Direct Threat to Financial Infrastructure PIX & Billetera Móvil Active Exploitation: The PixRevolution trojan identified March 2026 actively hijacks PIX instant payments in Brazil by overlaying fake screens and diverting funds in real-time. The Enabler: The vulnerabilities in this report ismsEx SMS bypass, INSTALL\PACKAGES silent installer, exported SGPS location tracking provide the perfect infrastructure for such malware to operate undetected. 2FA Bypass: CVE-2021-39658 allows malware to read or intercept SMS verification codes without permission, rendering traditional 2FA useless for banking apps.
C. Enterprise & Supply Chain Risk MDM Evasion: Corporate Mobile Device Management MDM systems rely on the security\patch string to enforce compliance. The FOTA spoofing mechanism ensures that compromised devices report "Compliant" status while running vulnerable firmware, allowing them to bypass corporate security gates. Data Exfiltration: The com.motorola.bach.modemstats service with READ\LOGS and MANAGE\NETWORK\POLICY can be weaponized to exfiltrate corporate data over hidden backchannels that ignore data usage limits.
D. The "Fake Patch" Deception False Security: Users receive notifications stating "Security Update Installed," but the underlying binaries dated March 18, 2026 remain vulnerable. This erodes trust in the Android ecosystem and leaves users exposed to known exploits. Regulatory Violation: This practice likely violates consumer protection laws in Mexico, Brazil, and the EU, as it constitutes a material misrepresentation of product security.
Systemic Pre-Installed Backdoors in Unisoc T606/T616 Enable Redundant, Zero-Click, Pre-Auth Takeover with Silent Malware Deployment in LATAM \CVSS 3.1\: 9.8 Critical \AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\ \CWE\: CWE-250, CWE-732, CWE-912, CWE-1220, CWE-276, CWE-269 \Affected\: Motorola Moto G04s, G24, G34, E24 + all Unisoc T606/T616, Android 11-13, LATAM 2024-2025 \1. Executive Summary\ "Operation Silent Rescue" identifies a \systemic attack chain affecting millions of budget Android devices in Latin America\. The vulnerability is not a single bug but a \convergence\ of: 1. \Unpatchable Hardware Flaws\: Permanent BootROM exploits CVE-2022-38694. 2. \Remote Network Vectors\: Modem RCE via rogue cell towers CVE-2025-31718. 3. \Privileged System Backdoors\: Pre-installed apps \com.spreadtrum.sgps\, \com.android.stk\, \com.dti.amx\, \com.inmobi.installer\ with exported components and \God-mode permissions\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. This chain allows an attacker to move from \remote network access to full system root, persistent surveillance, and financial fraud without user interaction\. The risk is exacerbated in Latin America due to delayed security patches and high reliance on these devices for mobile banking. \2. The Attack Chain: Technical Breakdown\ \Phase 1: The Foundation (Hardware & Network)\ - \CVE-2022-38694 (BootROM)\: Unpatchable flaw in Unisoc T606/T616 allowing arbitrary code execution during boot. \Impact\: Permanent rootkits, bypass of Secure Boot. - \CVE-2025-31718 (Modem RCE)\: Remote code execution via malformed LTE signals. \Impact\: Over-the-air initial access \AV:N\ without user interaction. \Phase 2: The Escalation Bridges (Exported System Apps)\ Once initial access is gained, the following system apps act as \force multipliers\, escalating privileges from "modem context" to "full system control": \\Component\\ \\Package Name\\ \\Critical Flaw\\ \\Role in Chain\\ \\SGPS Middleware\\ \com.spreadtrum.sgps\ Exported Receiver. \InstallDate: 2008-12-31\. \REBOOT\ permission. \\Primary LPE Vector\\. Triggers via code \2266\. Enables \NMEA2SOCKET\. \\SIM Toolkit\\ \com.android.stk\ Exported Receiver. Runs in \com.android.phone\. \\Financial Fraud\\. Pre-auth phishing via \BootCompletedReceiver\. \\Modem Stats\\ \com.motorola.bach.modemstats\ Exported \READ\LOGS\, \MODIFY\PHONE\STATE\. \persistent=true\. \\C2 & Persistence\\. Hidden backchannel + call interception. \\Digital Turbine\\ \com.dti.amx\ \INSTALL\PACKAGES\, \WRITE\SECURE\SETTINGS\. \\Payload Delivery 1\\. Silently installs banking trojans. Disables Play Protect. \\InMobi Installer\\ \com.inmobi.installer\ Exported \InstallationService\. \QUERY\ALL\PACKAGES\. \\Payload Delivery 2\\. Public API for silent installation. \\Redundant backdoor\\. \Phase 3: The Payload (Surveillance & Fraud)\ - \Financial Theft\: Use \INSTALL\PACKAGES\ to drop banking trojans. Use \STK\ to send premium SMS or intercept 2FA codes. - \Surveillance\: Use \SGPS\ for real-time location tracking. Use \ModemStats\ for call interception and IMSI catching. - \Persistence\: Use \BootCompletedReceiver\ in STK, InMobi, DT to ensure malware survives reboots. Use BootROM to survive factory resets. \
In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed..
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In dpc modem, there is a possible system crash due to null pointer dereference. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In nr modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In cplog service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed.
In cplog service, there is a possible system crash due to null pointer dereference. This could lead to local denial of service with no additional execution privileges needed.
In engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed.