Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unpatched OnePlus Flaws Exposed: A Lethal Combination of Vulnerabilities Leaves Android Apps Root Access Without Permissions




Unpatched OnePlus Flaws Exposed: A Lethal Combination of Vulnerabilities Leaves Android Apps Root Access Without Permissions

A recent report has exposed two critical vulnerabilities in OnePlus's OxygenOS, a popular Android operating system. The discovered flaws, which were chained together by a researcher to gain root access, have left installed Android apps able to bypass traditional security measures and gain control over the device without any special permissions. The attack is local, but the potential for harm is still very real, and it is crucial that users take immediate action to protect themselves. A fix is scheduled, but users should remain vigilant until then.

  • Two critical vulnerabilities have been discovered in OnePlus's OxygenOS, a popular Android operating system, leaving Android apps able to bypass traditional security measures and gain control over the device without permissions.
  • A malicious app can be installed and running on the phone before it can be launched over the internet, making it nearly undetectable.
  • The attack requires no permissions and shows no prompt to the user, emphasizing the severity of the vulnerability.
  • There is currently no evidence to suggest that anyone has used these flaws in a real attack, but the potential for harm is still very real.
  • OnePlus has acknowledged the flaws and assured that a fix is scheduled, but the company's approach to vulnerability disclosure has been called into question.
  • The incident serves as a stark reminder of the importance of cybersecurity awareness and the need for manufacturers to prioritize the security of their devices.



  • Unpatched OnePlus Flaws Exposed: A Lethal Combination of Vulnerabilities Leaves Android Apps Root Access Without Permissions

    In a disturbing revelation that has sent shockwaves throughout the cybersecurity community, a recent report has exposed two critical vulnerabilities in OnePlus's OxygenOS, a popular Android operating system. The discovered flaws, which were chained together by a researcher to gain root access, have left installed Android apps able to bypass traditional security measures and gain control over the device without any special permissions.

    The researcher, Rasmus Moorats, a renowned mobile security expert, discovered the first flaw in a OnePlus service called AtlasService, which is responsible for gathering debugging data, running as root, and accepting calls from any app without checking who is calling. Moorats found that a crafted call could reach a OnePlus debugging tool that would take the app's text and drop it, unchecked, into a system command, effectively granting the app root access within a restricted system zone called dumpstate. This zone, while not offering full root privileges, was sufficient to allow the app to execute system-level commands and gain control over the device.

    The second flaw, which Moorats discovered in a OnePlus hardware helper called olc2, was even more alarming. This service was shipped with a command that executed any shell instruction it received, its only guard being that the caller must already be root. Moorats demonstrated how the first flaw provided the necessary root access, allowing the malicious app to execute the command and gain all low-level Linux privileges, including the ability to load kernel code. This, in turn, gave the app control of the device at the system level, effectively making it a fully-rooted device.

    The attack is local, meaning that the malicious app must be installed and running on the phone first, before it can be launched over the internet. However, once installed, the app requires no permissions and shows no prompt to the user, making it nearly undetectable. Moorats confirmed that the attack worked on a stock phone that had not been modified, further emphasizing the severity of the vulnerability.

    It is worth noting that there is currently no evidence to suggest that anyone has used these flaws in a real attack. However, the potential for harm is still very real, and it is crucial that users take immediate action to protect themselves. As of Moorats's disclosure, OnePlus had assigned no CVE (Common Vulnerability and Exposure) and released no fix, and no OnePlus advisory naming the flaws could be found. Until a fix ships, the one practical defense is to install apps only from trusted sources, as the attack requires a malicious app on the phone to get started.

    This discovery is not an isolated incident, as it is part of a larger trend of vulnerabilities in popular Android operating systems. In August, another researcher, Lukas Maar, demonstrated a different technique that took a no-permission app to root locked phones running the latest firmware from Samsung, Xiaomi, OPPO, OnePlus, and Realme. This highlights the need for timely and effective patches, as well as for users to be vigilant in their app selection and installation practices.

    OnePlus has acknowledged the flaws and has assured that a fix is scheduled. However, the company's approach to vulnerability disclosure has been called into question. In May, when Moorats first reported the flaws, OnePlus confirmed them but claimed sole control over disclosure and warned that publishing without permission could result in legal liability. Moorats, however, chose to publish the details of the flaws anyway, citing the need to inform the public about the vulnerabilities and the importance of transparency in the cybersecurity community.

    This incident serves as a stark reminder of the importance of cybersecurity awareness and the need for manufacturers to prioritize the security of their devices. As the threat landscape continues to evolve, it is crucial that users, manufacturers, and researchers work together to identify and address vulnerabilities, and to develop effective strategies for mitigating the risks associated with them.

    In the coming weeks and months, it is expected that this vulnerability will be addressed through a patch, and that users will be able to install a fix to protect themselves. Until then, it is essential for users to remain vigilant and to take steps to protect themselves against potential attacks. By staying informed and taking proactive measures, users can significantly reduce the risk of falling victim to this and other similar attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unpatched-OnePlus-Flaws-Exposed-A-Lethal-Combination-of-Vulnerabilities-Leaves-Android-Apps-Root-Access-Without-Permissions-ehn.shtml

  • https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html


  • Published: Thu Sep 24 15:34:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us