8 flaws in the chip inside four phones sold in Japan (CVE-2026-21548)
UNISOC disclosed eight chip flaws on August 1, 2026. The T8100 ships in four phones sold in Japan. All eight only cut connectivity, but no patch date exists.
Table of contents
UNISOC disclosed eight chip flaws on August 1, 2026. The T8100 ships in four phones sold in Japan. All eight only cut connectivity, but no patch date exists.
On August 1, 2026, the Chinese chipmaker UNISOC published eight vulnerabilities in its own processors. One of the affected chips, the T8100, sits inside four phones currently sold in Japan by Y!mobile, SoftBank, Rakuten Mobile, and IIJmio β entry-level handsets released between December 2025 and March 2026 at roughly Β₯20,000 to Β₯30,000.
The conclusion first. All eight only stop the phone from communicating. None of them expose photos, contacts, or passwords. UNISOC's own scoring rates confidentiality impact and integrity impact as "none" for every one of the eight. There is no reason to replace a handset over this.
The problem lies elsewhere. There is currently nothing an owner can do about any of it. UNISOC's bulletin lists no patch version and no delivery date; the only instruction it carries is a line telling device manufacturers to use a support contact form. No configuration workaround is offered either. As of August 3, none of the four affected models had received an August security update.
And one more thing. As of August 3 we could find no Japanese-language coverage of these eight at all β nothing on ITmedia, Ketai Watch, Security NEXT, or ScanNetSecurity, and no Hatena Bookmark entries. This despite the affected chip shipping in phones sold over the counter by Japanese carriers.
Whether your phone is affected
That is the only question worth answering first. We checked the official specification pages for handsets sold in Japan against the chip models UNISOC named.
| Model | Sold by | Chip | Released | Android | Affected |
|---|---|---|---|---|---|
| nubia S2 (A504ZT) | Y!mobile | T8100 | Dec 4, 2025 | 15 | Yes |
| nubia S2R (Z6305R) | Rakuten Mobile | T8100 | Dec 2025 (preorder Dec 2) | 15 | Yes |
| nubia S2e (A507ZT) | SoftBank business Y!mobile business | T8100 | Dec 1, 2025 | 15 | Yes |
| nubia S2 Lite | IIJmio BIC SIM | T8100 | Mar 19, 2026 | 15 | Yes |
| nubia S 5G (A403ZT) | Y!mobile | T760 | Jan 16, 2025 | 15 (shipped with 14) | No |
Despite the similar name, the nubia S 5G is not affected. It carries a T760, which is not among the models UNISOC listed. Same brand, same price bracket, easy to confuse β but unrelated to this bulletin.
The chips UNISOC named are T8100, T9100, T8200, and T8300 on the phone side (covering Android 13 through 16), plus UDX710 for connectivity hardware. Of these, only the T8100 could be traced to handsets on sale in Japan. Whether any T9100, T8200, or T8300 device ships there could not be established from official sources. UDX710 goes into mobile routers and similar equipment, but most routers sold in Japan do not publish their chipset, so that could not be determined either. That means "we looked and could not tell," not "none exist."
To check your own device, the carrier specification pages are definitive. Y!mobile's nubia S2, Rakuten Mobile's nubia S2R, SoftBank business's nubia S2e, and IIJmio's nubia S2 Lite all state "UNISOC T8100" explicitly.
What the eight actually do
All eight are in the part of the phone called the modem β a dedicated processor that talks to cell towers over the air, running independently of the Android world you actually see on screen. Every call and every byte of mobile data passes through it.
In each case, the modem processes incoming data without adequately checking it first. Fed a malformed message by something impersonating a cell tower, the modem's processing breaks down. UNISOC describes the outcome as "remote denial of service." In plain terms: someone nearby can knock out your phone's connectivity over the air.
All eight score 7.5 out of 10, which UNISOC classes as High. Break the score down and it reads confidentiality impact none, integrity impact none, availability impact high. That 7.5 comes entirely from one property β no credentials and no user interaction are needed to cut off communication over the network. Nothing in it reflects data being read or altered.
One honest gap. UNISOC does not say what the phone does after connectivity drops. Whether a restart clears it, whether the device sits without signal, whether it can be knocked down repeatedly as long as it stays in range β the bulletin does not go into that, and neither can this article. We are leaving it unknown rather than guessing.
CVE-2026-21548: input validation in the 5G modem
The only one of the eight described differently. UNISOC's wording is "nr modem" β nr being the abbreviation for the 5G radio standard, so this is the part handling 5G specifically. The other seven say only "modem." Affected chips are T8100, T9100, T8200, and T8300 on Android 13 through 16.
This entry carries a caveat in its description: "with System execution privileges needed." Yet the severity breakdown classifies it as requiring no privileges at all β the prose and the score contradict each other. We pulled the CVE record itself to check, and UNISOC has published nothing that would settle which is correct.
CVE-2026-21549 / 21550 / 21551 / 21552 / 21553: five with identical text
For these five, UNISOC published essentially the same description: one sentence saying the modem has an input validation flaw that could lead to remote denial of service. Affected chips (T8100, T9100, T8200, T8300), severity (7.5), and weakness class (improper input validation) are identical across all of them. We checked the NVD records for CVE-2026-21550, CVE-2026-21551, CVE-2026-21552, and CVE-2026-21553 individually and found nothing that distinguishes one from another.
Separate CVE numbers imply separate underlying defects. What differs between them, from the outside, is unknowable. This is not unique to UNISOC β it is how chipmakers routinely disclose modem flaws. Withholding detail denies attackers a head start, but it also removes any way for an owner to confirm whether their own device has been fixed.
CVE-2026-21554 / 21555: connectivity hardware, not phones
The last two target something different. These two and CVE-2026-21555 affect the UDX710, which runs Yocto β a flavour of Linux β rather than Android. That chip goes into mobile routers, fixed-wireless home internet boxes, and industrial IoT equipment.
The flaw is the same as the other six: improper input validation in the modem, denial of service, severity 7.5. The consequence lands differently, though. A phone owner notices immediately when connectivity dies; a box sitting on a shelf can stay down with nobody noticing. Which mobile routers sold in Japan carry a UDX710 could not be determined, because vendors there generally do not publish the chipset.
Who would use this, and what it gets them
Exploiting any of the eight requires someone physically near the target device who can stand up a fake cell tower. This is not something reachable from anywhere on the internet. The hardware to impersonate a tower can be assembled from commercial radio equipment and published software, but radio only travels as far as radio travels β attacker and target have to be in the same place. No automated program sweeping the world is going to stumble into this.
What that person gets is the ability to cut off phones within range, and nothing more. No reading, no altering. The use case, if there is one, is narrow: silencing communications in a specific place at a specific moment, where someone does not want calls made. What it cannot do is extract anyone's photos or banking details. For ordinary users, it is genuinely hard to construct a realistic harm scenario here.
Consistent with that, no exploitation has surfaced. We checked CISA's catalog of vulnerabilities confirmed to be under attack and none of the eight appear. No proof-of-concept code was found, and no reports of attacks. That is a fair basis for saying this one is not urgent. The caveat worth stating: modem attacks look like bad reception to the person holding the phone, so this class of problem is unusually unlikely to surface as a reported incident in the first place.
There is no fix available to the people affected
Low practical risk aside, something about this one does not sit right: nobody has said how to fix it.
UNISOC's bulletin carries no patch version and no delivery date. What it does carry is a line directing device manufacturers to a support contact form β addressed to the companies building handsets, not to the people holding them. No settings change is offered to reduce exposure in the meantime.
So what about the device side? Here is where each carrier stood as of August 3.
| Model | Latest update | Shipped | Stated contents | August |
|---|---|---|---|---|
| nubia S2 (Y!mobile) | Build 1.4.1_U | Jun 30, 2026 | Charging fix, "security improvements" | Not shipped |
| nubia S2R (Rakuten) | MyOS15.2.3 | Jul 27, 2026 | "Security improvements" | Not shipped |
| nubia S2e (SoftBank) | Build 1.3.0_U | Mar 18, 2026 | "Security improvements" and other fixes | Not shipped |
| nubia S2 Lite (IIJmio) | No published update history found | β | β | Not shipped |
None of the four has an August security update. Given the bulletin landed on August 1, that in itself is unremarkable. What stands out is something else: every one of these notices describes its contents as "security improvements" and stops there. None states an Android security patch level β the standard marker showing which month's fixes a build contains.
Written that way, when an update does arrive, an owner has no means of telling whether it addresses these eight. Install what you are offered; there is no further step available. That is the realistic conclusion.
We also checked Android's monthly bulletin. Google publishes chipmaker vulnerabilities each month, and UNISOC entries have appeared in past editions. But the August 2026 edition was not yet published as of August 3, so whether these eight are included is unknown. The most recent entry on Android's security bulletin index was July's.
Sold in Japan, reported by nobody in Japanese
What stood out while reporting this was not the vulnerability. It was the gap in coverage.
UNISOC holds somewhere between a tenth and a seventh of global smartphone chip shipments. It lacks the name recognition of Qualcomm or MediaTek, but in budget handsets its position is solid. In February 2026 it issued a Japanese-language press release announcing entry into that market, and phones carrying its chips now sit in Y!mobile, SoftBank, Rakuten Mobile, and IIJmio storefronts.
Even so, we could find no Japanese-language article covering these eight as of August 3. Nothing on ITmedia, Ketai Watch, Security NEXT, or ScanNetSecurity; searching Hatena Bookmark for "UNISOC" turns up no entry for this. The same outlets covered the nubia S2 Lite launch β but not the flaws in its chip.
To be precise about it: this is not a claim that UNISOC flaws never get Japanese coverage. A different UNISOC vulnerability found in 2022 was reported by PC Watch and Mynavi, and a March 2026 issue in the T612 chip was covered in Japanese too. The absence applies to these eight specifically.
Why the gap forms is not mysterious. Chipmaker disclosures come in English only, in the form of one-sentence entries, leaving very little for a reporter to work with. And vendors without a household name simply do not get followed the way Qualcomm and Apple do. Still β when the affected chip ships in phones a country's own carriers sell over the counter, that gap is not one to leave alone. It rhymes with the problem covered in our OSS supply chain scanner: not knowing what you are actually running.
What to do now
If you use a nubia S2, S2R, S2e, or S2 Lite, there is no urgent action to take. All eight only sever connectivity, none of them reach the contents of the device, and no exploitation has been observed.
Three things, and that is all. One, install updates when they are offered β you can also check manually under Settings, System. Two, install them even though the notes say only "security improvements"; with no detail published, there is no basis for declining either. Three, if connectivity drops repeatedly and does not recover, report it to your carrier. Whether it relates to this is unknowable, but having the symptom on record is worth something.
There is no case for replacing the handset. Nothing guarantees the next chip is free of the same class of flaw, and modem vulnerabilities appear in Qualcomm and MediaTek parts nearly every month. Nothing here makes UNISOC uniquely unsafe.
This article reflects what could be confirmed as of August 3. If UNISOC publishes more detail, if Android's August bulletin includes these, or if any carrier ships an update containing the fix, we will add it.
Sources
- γ»UNISOC β Product Security Bulletin (August 1, 2026)
- γ»UNISOC β Product Security Bulletin index
- γ»NVD β CVE-2026-21548
- γ»NVD β CVE-2026-21549
- γ»NVD β CVE-2026-21550
- γ»NVD β CVE-2026-21551
- γ»NVD β CVE-2026-21552
- γ»NVD β CVE-2026-21553
- γ»NVD β CVE-2026-21554
- γ»NVD β CVE-2026-21555
- γ»MITRE CVE Services β the CVE-2026-21548 record
- γ»Y!mobile β nubia S2 specifications
- γ»Y!mobile β nubia S2 software update (June 30, 2026)
- γ»Rakuten Mobile β nubia S2R detailed specifications
- γ»nubia Japan β nubia S2R software update history
- γ»SoftBank business β nubia S2e
- γ»SoftBank β nubia S2e software update (March 18, 2026)
- γ»nubia Japan β nubia S2 Lite
- γ»Android β Security Bulletins
- γ»CISA β Known Exploited Vulnerabilities Catalog

Makoto Horikawa
Backend Engineer / AWS / Django