Windows 11’s strongest security defenses can be bypassed without a screwdriver
Researchers found a script-only attack, 'Download More RAM', that rewrites DIMM configuration chips to bypass Windows 11 VBS and HVCI security boundaries.
Researchers at the University of Birmingham and Durham University showed that overwriting configuration data on unprotected DDR4/DDR5 module chips creates memory aliases that let attackers with existing privileged access defeat Virtualisation-based Security and HVCI, re-enable blocklisted drivers, kill EDR, and bypass group policy. Microsoft assigned CVE-2026-23670 and shipped mitigations in its April 2026 updates; systems with Secure Boot enabled are protected. Affected unprotected product lines are estimated at more than half of the high-performance consumer memory market and over 70% of the gaming segment.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Unisoc modem firmware flaw CWE-1189 allows VoLTE video call RCE chain to gain full Android kernel access on T606/T612/T7250 chipsets; no patch yet.
SSD Secure Disclosure published the second stage of an exploit chain, first disclosed in March 2026, that achieves full Android kernel access on Unisoc modem firmware via a VoLTE video call. The privilege-escalation flaw, classified as CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip), exploits shared physical memory between modem and application processor with no hardware boundary, letting modem code map the entire 32-bit address space and modify Android kernel pages via ARM Memory Protection Unit registers. Confirmed affected chipsets include Unisoc T606 (Motorola E13), T612 (Realme C33), and T7250 (Xiaomi Redmi A5), sold across more than 140 countries. No CVE has been assigned, the August 2026 Android Security Bulletin does not address it, and Unisoc has not responded to researchers; exploitation requires an attacker-controlled private 4G network and a victim answering the call.