Hackers could disrupt millions of smartphones by abusing this critical bug

Smartphones
(Image credit: Getty Images)

A serious vulnerability present in more than a tenth of the world’s mobile phones could allow threat actors to kill all communications in a certain location, researchers have found.

Security analysts from Check Point Research (CPR) found the flaw in the UNISOC modem which, as the researchers claim, can be found in 11% of all the smartphones in the world (predominantly in Africa and Asia). 

The modem allows for cellular communication, and by leveraging the flaw, the attacker can remotely deny modem services and block communication.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Critical UNISOC modem vulnerability

The flaw is now being tracked as CVE-2022-20210, and carries a vulnerability score of 9.4 out of 10 as a reflection of its severity.

According to CPR, the vulnerability was discovered in NAS message handlers, which could be used to disrupt radio communication through a malformed packet. Apparently, military or state-sponsored hackers would be able to use it to kill all communications in specific locations. 

Since the discovery of the flaw, a patch has been issued, and all smartphone users are urged to keep their devices up to date at all times. 

“There is nothing for Android users to do right now, though we strongly recommend applying the patch that will be released by Google in their upcoming Android Security Bulletin,” said Slava Makkaveev, Reverse Engineering & Security Research at Check Point Software. 

Although not as high-profile as software flaws, hardware flaws are just as frequent, and just as dangerous. Earlier this month, a security flaw was discovered in Qualcomm’s MSM chips, which could have allowed threat actors to access SMS messages and phone conversations in a third of the world’s Android endpoints. 

This vulnerability, tracked as CVE-2020-11292, was also discovered by Check Point Research, who discovered it while using a process known as fuzzing to test Qualcomm's mobile station modem (MSM) for flaws in its firmware.

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
MediaTek
MediaTek reveals host of security vulnerabilities, so patch now
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
A VPN runs on a mobile phone placed on a laptop keyboard
Major new online tunneling vulnerability could put millions of devices at risk
AMD logo
Security flaw means AMD Zen CPUs can be "jailbroken"
An abstract image of a lock against a digital background, denoting cybersecurity.
Apple CPU security issue could let hackers steal user data from browsers
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Latest in News
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
An iPhone running iOS 18 on a purple and blue background
iOS 18.4 could launch soon with a major upgrade to your iPhone’s notifications
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon