{"id":198447,"date":"2025-10-14T02:31:10","date_gmt":"2025-10-14T02:31:10","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/198447\/"},"modified":"2025-10-14T02:31:10","modified_gmt":"2025-10-14T02:31:10","slug":"theres-already-a-new-way-to-enable-volte-on-pixel-phones","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/198447\/","title":{"rendered":"There\u2019s already a new way to enable VoLTE on Pixel phones"},"content":{"rendered":"<p><img class=\"e_Ug\" decoding=\"async\" loading=\"eager\"  title=\"google phone app incoming call screen pixel 10 pro\"  alt=\"Incoming call screen with Google's Calling Cards.\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/08\/google-phone-app-incoming-call-screen-pixel-10-pro-scaled.jpg\"\/><\/p>\n<p>Joe Maring \/ Android Authority<\/p>\n<p>TL;DR<\/p>\n<p>Google broke the Pixel IMS app that enabled VoLTE\/VoWiFi on unsupported carriers, but the developer has already released a new workaround.<br \/>\nGoogle\u2019s October update patched a loophole that the app exploited, specifically blocking the \u201cshell\u201d user from calling a restricted internal API.<br \/>\nThe new fix bypasses this restriction by \u201claundering\u201d the API call through another component, so the system doesn\u2019t detect it coming from shell.<\/p>\n<p>Back in early 2023, a Korean developer released an app called \u201cPixel IMS\u201d that lets Pixel users enable VoLTE and VoWiFi on any carrier. This app is useful for people who <a href=\"https:\/\/www.androidauthority.com\/imported-google-pixel-phone-mistake-3562340\/\" rel=\"nofollow noopener\" target=\"_blank\">import Pixel phones<\/a> into certain countries, as Pixels lack VoLTE and VoWiFi support in many of the markets where they aren\u2019t directly sold by Google. However, Google pushed an update last week that patched the loophole the Pixel IMS app used to forcefully enable VoLTE and VoWiFi, <a href=\"https:\/\/www.androidauthority.com\/pixel-ims-broken-october-update-3606444\/\" rel=\"nofollow noopener\" target=\"_blank\">breaking the app in the process<\/a>. Users who depended on the app to enable these crucial calling features were disheartened by Google\u2019s action, but fortunately for them, a new workaround has already been found.<\/p>\n<p>Don\u2019t want to miss the best from Android Authority?<\/p>\n<p><a href=\"https:\/\/andauth.co\/AAGooglePreferredSource\" class=\"e_Wn\" target=\"_blank\" rel=\"noreferrer nofollow noopener\"><img class=\"e_Ug\" decoding=\"async\" loading=\"lazy\"  title=\"google preferred source badge light@2x\"  alt=\"google preferred source badge light@2x\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/google_preferred_source_badge_light@2x.png\"\/><img class=\"e_Ug\" decoding=\"async\" loading=\"lazy\"  title=\"google preferred source badge dark@2x\"  alt=\"google preferred source badge dark@2x\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/google_preferred_source_badge_dark@2x.png\"\/><\/a>How Google tried to stop Pixel users from enabling VoLTE everywhere, and why it failed<\/p>\n<p>Last week, Google released the <a href=\"https:\/\/www.androidauthority.com\/october-2025-pixel-update-3605572\/\" rel=\"nofollow noopener\" target=\"_blank\">October 2025 update<\/a> for Pixel phones to address a variety of display and UI issues. Although this month\u2019s security bulletin didn\u2019t mention any vulnerabilities, Google quietly included a patch that closed the specific loophole used by the Pixel IMS app to enable VoLTE and VoWiFi. This patch caused the app to crash whenever users tried to toggle VoLTE or VoWiFi, with a crash log stating that \u201coverrideConfig cannot be invoked by shell.\u201d<\/p>\n<p>overrideConfig is an internal API in Android\u2019s telephony framework that allows callers to override the <a href=\"https:\/\/developer.android.com\/reference\/android\/telephony\/CarrierConfigManager\" target=\"_blank\" rel=\"nofollow noopener\">carrier configuration<\/a> \u2014 a set of carrier-specific keys the OS reads to determine which connectivity features to enable. Normally, carriers provide these keys directly, but the overrideConfig API can override them. Since third-party apps are not meant to have this level of control, the overrideConfig API is <a href=\"https:\/\/cs.android.com\/android\/platform\/superproject\/main\/+\/main:frameworks\/base\/telephony\/java\/com\/android\/internal\/telephony\/ICarrierConfigLoader.aidl;l=33\" target=\"_blank\" rel=\"nofollow noopener\">not public<\/a>.<\/p>\n<p>Instead, overrideConfig can only be called by apps holding the MODIFY_PHONE_STATE permission, which is restricted to privileged system apps. So how did Pixel IMS use this API? It leveraged <a href=\"https:\/\/www.androidauthority.com\/best-open-source-android-apps-3565444\/\" rel=\"nofollow noopener\" target=\"_blank\">Shizuku<\/a>, an open-source tool that allows other apps to run as the \u201cshell\u201d user. The shell user has elevated privileges necessary for testing and debugging apps through the <a href=\"https:\/\/www.androidauthority.com\/how-to-use-adb-android-3260397\/\" rel=\"nofollow noopener\" target=\"_blank\">Android Debug Bridge (ADB)<\/a>. Because platform developers at Google also use ADB to test new configurations, the shell app was granted the MODIFY_PHONE_STATE permission.<\/p>\n<p><img class=\"e_Ug\" decoding=\"async\" loading=\"lazy\"  title=\"Pixel IMS app enable VoLTE\"  alt=\"Pixel IMS app enable VoLTE\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/Pixel-IMS-app-enable-VoLTE-scaled.png\"\/><img class=\"e_Ug\" decoding=\"async\" loading=\"lazy\"  title=\"Pixel IMS enabling VoLTE on unsupported Korean carrier\"  alt=\"Pixel IMS enabling VoLTE on unsupported Korean carrier\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/10\/Pixel-IMS-enabling-VoLTE-on-unsupported-Korean-carrier.jpg\"\/><\/p>\n<p>The Pixel IMS app exploited this to use the overrideConfig API, a loophole that Google left untouched for over two and a half years. Recently, however, Google classified this loophole as a high-severity privilege escalation vulnerability. Despite this classification, it wasn\u2019t deemed a high enough risk under the new <a href=\"https:\/\/www.androidauthority.com\/android-risk-based-security-updates-3597466\/\" rel=\"nofollow noopener\" target=\"_blank\">Risk-Based Update System (RBUS)<\/a> to be included in this month\u2019s security bulletin, but Google rolled out the fix nonetheless.<\/p>\n<p>Google\u2019s fix added a check to the overrideConfig API, blocking access if the calling process was the shell user. This broke the Pixel IMS app, as it relied on running as the shell user to call the API.<\/p>\n<p>Over the weekend, the developer <a href=\"https:\/\/github.com\/kyujin-cho\/pixel-volte-patch\/releases\/tag\/1.3.0\" target=\"_blank\" rel=\"nofollow noopener\">implemented a solution<\/a> that bypasses Android\u2019s new restriction. Instead of making a direct call to the overrideConfig API, Pixel IMS <a href=\"https:\/\/github.com\/kyujin-cho\/pixel-volte-patch\/blob\/8ceda82c71624145645672d044aa2813f7c4194b\/app\/src\/main\/java\/dev\/bluehouse\/enablevolte\/Moder.kt#L147\" target=\"_blank\" rel=\"nofollow noopener\">now uses<\/a> an indirect method, launching an Instrumentation component to make the API call on its behalf. This circumvents the restriction because the call no longer appears to come from the shell user; in essence, the app is laundering its API call through a different, \u201cclean\u201d user.<\/p>\n<p>Of course, this new method isn\u2019t foolproof. Google could patch it in several ways, with the most effective being the complete removal of the MODIFY_PHONE_STATE permission from the shell app. This would be an effective killswitch, as the new loophole only works because the shell app still technically has the necessary permission to call the overrideConfig API.<\/p>\n<p>The question is, how aggressively will Google go after Pixel IMS and similar apps? Would a complete block of Pixel IMS stop you from importing a Pixel phone? Let us know why or why not in the comments below!<\/p>\n<p>Thank you for being part of our community. Read our\u00a0<a class=\"c-link\" href=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\" data-stringify-link=\"https:\/\/www.androidauthority.com\/android-authority-comment-policy\/\" data-sk=\"tooltip_parent\">Comment Policy<\/a> before posting.<\/p>\n","protected":false},"excerpt":{"rendered":"Joe Maring \/ Android Authority TL;DR Google broke the Pixel IMS app that enabled VoLTE\/VoWiFi on unsupported carriers,&hellip;\n","protected":false},"author":2,"featured_media":198448,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[59,844,2305,86,56,54,55],"class_list":["post-198447","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-gb","tag-google","tag-google-pixel","tag-technology","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/198447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=198447"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/198447\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/198448"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=198447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=198447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=198447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}