Of all the processor designers, those of Unisoc are characterized by promoting the cheapest mobiles. And they suffer from a serious security problem according to the latest research: the base band of these chips, the component in charge of managing mobile connectivity, would be vulnerable to third-party attacks.
Talking about mobile processors usually brings to mind two brands: Qualcomm and MediaTek. Both are fighting to equip all families of telephones, whether they are the most high-end or the most accessible. Samsung does the same with its chips, the Exynos. Yes there is a fourth competitor that tends to go more unnoticed: Unisoc
An exploitable modem fault
With such a quantity of components that accumulates a smartphone, there are some who generally open the door to others. The processor or SoC (System on a chip) is responsible for processing image information, manages artificial intelligence, generates 3D graphics for games and, not least, it incorporates a modem that allows the phone to communicate with other devices. Unisoc is no stranger to this construction.
As Check Point Research discovered, processors distributed by Unisoc are vulnerable to an attack on their baseband, the modem responsible for handling mobile connectivity. According to a detailed investigation, an intruder can block the connection of said mobile based on launching attacks against the aforementioned baseband. Unisoc chips carry the vulnerability since March 2022.
Due to the vulnerability, Unisoc processors, distributed in the cheapest mobiles due to their reduced pricethey run the risk of having their remote connectivity blocked, a hacking attack could also be executed which would end up giving access to the rest of the phone.
Unisoc assigned the failure a critical scale; which led him to fix it in the latest versions of his firmware. The problem is to get this update on the phones concerned: given the economy of these phones, it is very rare for brands to relaunch their software. Unisoc patched the vulnerability in May.
Through | Searching for checkpoints