Unpatched OnePlus Flaws Allow Root Access Without Permissions
Android devices from OnePlus and OPPO are vulnerable to privilege escalation through preinstalled apps. A security researcher demonstrated how two chained flaws can grant full root access without user consent.
TL;DR
- Researcher exploited two unpatched flaws in OnePlus OxygenOS to gain root access
- Malicious apps can escalate privileges without requesting special permissions
- Vulnerabilities affect multiple OnePlus and OPPO devices running latest firmware
- Root access enables complete device control including system file modification
- Users should monitor installed apps and avoid untrusted sources
A critical security vulnerability discovered in OnePlus Android devices allows malicious applications to gain root-level access without requiring any special permissions. The flaw affects the latest OxygenOS versions and potentially impacts millions of users across both OnePlus and OPPO device lines.
Security researcher Rasmus Moorats successfully demonstrated how two separate vulnerabilities in OnePlus's proprietary software could be chained together to achieve complete system control. This type of privilege escalation attack represents a significant risk to enterprise mobility security, as it bypasses Android's built-in permission model entirely.
Technical Impact
- Two separate flaws in OnePlus software were chained to achieve root access
- No special permissions required from the malicious application
- Attack works on OnePlus 15 running latest OxygenOS firmware
- Root access allows complete control over device including system files
- Same vulnerabilities confirmed present in multiple OnePlus and OPPO devices
Enterprise Risk Considerations
- Organizations using OnePlus or OPPO devices face elevated mobile security risks
- Standard Android permission controls are completely bypassed by this exploit
- Malware could gain persistent access and exfiltrate sensitive corporate data
- Device integrity checks may not detect exploitation of these specific flaws
- IT administrators should inventory mobile device fleets for affected models
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.