Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
- ID
- 28236
- Status
- summarized
- Published
- 25 Sep 2026, 2:10 AM
- Fetched
- 25 Sep 2026, 3:17 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.5
- Created
- 25 Sep 2026, 3:19 AM
- Tags
- Audience
- developersvibe_coders
What happened
Researcher Rasmus Moorats chained two flaws in OnePlus's own software to root a OnePlus 15 running the latest OxygenOS using an installed app that requests no permissions: AtlasService accepts calls from any app, runs as root, and pipes app-controlled text unchecked into a system command (landing in the restricted dumpstate zone), and the olc2 hardware helper then executes any shell command from a root caller, granting full Linux privileges including loading kernel code. OnePlus confirmed both flaws in May and said the same issues affect many more OnePlus and OPPO devices without naming them, but no fix had shipped when Moorats published on September 24. In its reply, which Moorats published in full, OnePlus claimed the "exclusive final right of vulnerability disclosure," said researchers may not publish full technical details even after a fix, cited European cybersecurity rules as requiring makers to fix but not researchers to disclose, and warned it would "pursue relevant legal liabilities."
Why it matters
There is no patch and no list of affected models, so if your team or test bench uses OnePlus or OPPO handsets, the only current mitigation is not installing sideloaded or untrusted APKs — the attack is local and needs a malicious app running first. The bigger decision is procedural: if you or your team report a bug to a vendor, OnePlus's stated position is that it alone decides when and whether you may disclose, and it has threatened legal liability for publishing — worth knowing before you promise a timeline to users or file your next report.
Discussion angle
Vendors asserting an "exclusive final right of vulnerability disclosure" and citing EU rules to block publication — what should a small team do when it finds a bug in a platform it ships on, and does Malaysia's legal environment give researchers any protection at all?