A OnePlus 15 working the newest OxygenOS might be rooted by a malicious app the proprietor installs, one which asks for no particular permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s personal software program to achieve root entry, the very best degree of management over an Android cellphone.
OnePlus informed him the identical flaws have an effect on many extra of its personal units and people of OPPO, although it has not stated which.
OnePlus confirmed each flaws in Could. In the identical reply, the corporate informed Moorats that it alone decides when to make a flaw public and warned that publishing with out its permission may lead to authorized legal responsibility. He revealed on September 24 anyway, when OnePlus had launched no repair.
OnePlus set out its place within the reply, which Moorats revealed in full. It stated a repair was scheduled, however claimed “the unique remaining proper of vulnerability disclosure,” and informed him that even after a repair ships, researchers could not publish full technical particulars on their very own.
The corporate argued that European cybersecurity guidelines require makers to simply accept and repair studies however don’t permit researchers to reveal them with out the maker’s consent. It warned that if he revealed with out permission, OnePlus would “pursue related authorized liabilities in accordance with relevant legal guidelines.”
How the Assault Works
Moorats discovered the primary flaw in a OnePlus service referred to as AtlasService, which gathers debugging information, runs as root, and accepts calls from any app with out checking who is asking.
A crafted name reaches a OnePlus debugging device that takes the app’s textual content and drops it, unchecked, right into a system command. That fingers the app root, however solely inside a restricted system zone referred to as dumpstate, which can not do the whole lot root usually can.
The second flaw finishes the job. OnePlus ships one other service, a {hardware} helper referred to as olc2, with a command that executes any shell instruction it receives. Its solely guard is that the caller should already be root, which the primary flaw supplies.
This time, the command runs in a zone that grants all low-level Linux privileges, together with the flexibility to load kernel code, giving the app management of the system on the system degree.
Who Is Affected, and What You Can Do
The assault is native. A malicious app needs to be put in and working on the cellphone first, so it can’t be launched over the web. However as soon as it’s there, the app wants no permissions and exhibits the person no immediate, and it labored on a inventory cellphone Moorats had not modified.
There is no such thing as a proof that anybody has used the issues in an actual assault.
Moorats additionally confirmed the assault on an older OnePlus 12 Professional, and he expects the identical downside throughout OxygenOS 16 basically. OnePlus and OPPO construct their telephones on shared software program, which is why OnePlus’s warning coated each.
As of Moorats’s disclosure, OnePlus had assigned no CVE and launched no repair, and no OnePlus advisory naming the issues could possibly be discovered. Till a repair ships, the one sensible protection is the factor the assault must get began: set up apps solely from sources you belief, as a result of it can not run with out a malicious app on the cellphone.
By Moorats’s account, the disclosure ran over about 5 months:
- April 18, 2026: reported each flaws to OnePlus.
- Could 20: OnePlus confirmed them, claimed sole management over disclosure, and warned of authorized legal responsibility if he revealed.
- June 22: OnePlus gave an replace on its repair and requested him to carry off, and he agreed to not publish earlier than September 17.
- July 20 and September 11: he requested for updates and obtained no reply.
- September 24: he revealed.
Individually, this isn’t the one current case of an put in app reaching root on flagship Android telephones.
In August, Lukas Maar, a researcher on the safety agency Calif, confirmed a unique approach that took a no-permission app to root locked telephones working the newest firmware from Samsung, Xiaomi, OPPO, OnePlus, and Realme by attacking code the makers add to Android.
OnePlus has additionally been sluggish to reply researchers earlier than. In 2025, Rapid7 reported a separate OxygenOS flaw that permit any app learn a person’s texts, and stated OnePlus didn’t reply till the analysis was public.









