AI Weekly Malaysia

Back to items Summaries

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

ID
28236
Status
summarized
Published
25 Sep 2026, 2:10 AM
Fetched
25 Sep 2026, 3:17 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
25 Sep 2026, 3:19 AM
Tags
Audience
developersvibe_coders

What happened

Researcher Rasmus Moorats chained two flaws in OnePlus's own software to root a OnePlus 15 running the latest OxygenOS using an installed app that requests no permissions: AtlasService accepts calls from any app, runs as root, and pipes app-controlled text unchecked into a system command (landing in the restricted dumpstate zone), and the olc2 hardware helper then executes any shell command from a root caller, granting full Linux privileges including loading kernel code. OnePlus confirmed both flaws in May and said the same issues affect many more OnePlus and OPPO devices without naming them, but no fix had shipped when Moorats published on September 24. In its reply, which Moorats published in full, OnePlus claimed the "exclusive final right of vulnerability disclosure," said researchers may not publish full technical details even after a fix, cited European cybersecurity rules as requiring makers to fix but not researchers to disclose, and warned it would "pursue relevant legal liabilities."

Why it matters

There is no patch and no list of affected models, so if your team or test bench uses OnePlus or OPPO handsets, the only current mitigation is not installing sideloaded or untrusted APKs — the attack is local and needs a malicious app running first. The bigger decision is procedural: if you or your team report a bug to a vendor, OnePlus's stated position is that it alone decides when and whether you may disclose, and it has threatened legal liability for publishing — worth knowing before you promise a timeline to users or file your next report.

Discussion angle

Vendors asserting an "exclusive final right of vulnerability disclosure" and citing EU rules to block publication — what should a small team do when it finds a bug in a platform it ships on, and does Malaysia's legal environment give researchers any protection at all?

Top