Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
September 25, 2026
Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers
September 25, 2026
AI-Powered Botnet “DarkGate” Found Operating Inside Compromised Servers
September 25, 2026
Home/CyberSecurity News/OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access
CyberSecurity News

OnePlus OxygenOS Critical Flaws Let Zero-Permission Apps Gain Root Access

Key Takeaways Two critical vulnerabilities in OnePlus OxygenOS could allow Android applications with zero permissions to achieve root access on affected devices, including the OnePlus 15. The flaws...

David kimber
David kimber
September 25, 2026 3 Min Read
3 0

Key Takeaways

  • Two critical vulnerabilities in OnePlus OxygenOS could allow Android applications with zero permissions to achieve root access on affected devices, including the OnePlus 15.
  • The flaws exploit privileged system services, bypassing standard Android security mechanisms that restrict untrusted apps.
  • Successful exploitation grants attackers full control over a compromised device, enabling data theft, system modification, and security bypasses.
  • OnePlus has acknowledged the vulnerabilities, confirmed the report, and is working on a fix, which will likely extend to other OPPO terminal products.

Critical security flaws have been identified in the latest OxygenOS build, potentially allowing malicious Android applications to execute code with root privileges on OnePlus devices, including the new OnePlus 15. These vulnerabilities exploit privileged system services that are accessible to installed applications.

Table Of Content

  • Key Takeaways
  • OnePlus 15 Zero-Permission Flaws
  • What You Should Do

The significance of these vulnerabilities stems from their ability to circumvent Android’s core permission model. Typically, Android apps require explicit user consent for accessing sensitive device functions. An application requesting no permissions is generally assumed to have limited capabilities. However, the reported OxygenOS flaws bypass this fundamental security expectation by abusing components that already operate with elevated privileges within the system.

Security researcher Rasmus Moorats initially reported these findings to OnePlus. The company’s security team subsequently validated the report and indicated that remediation efforts were underway. In an email dated May 20, 2026, the OnePlus Security Response Center said the issues affect “all series of OPPO terminal products with universal security risks.” This statement suggests that the vulnerable components might be shared across the broader OPPO device ecosystem, potentially widening the scope of impact.

OnePlus 15 Zero-Permission Flaws

The attack vector for these vulnerabilities centers on specific privileged OxygenOS services exposed to applications installed on a device. If such a service fails to adequately verify the caller’s identity, enforce signature-level permissions, or validate input, an untrusted application can send specially crafted requests. These requests are designed to trigger dangerous operations within the privileged service.

The alleged outcome of a successful exploit is the execution of attacker-controlled code with root privileges. Root access represents Android’s highest privilege level, granting an attacker comprehensive control over the compromised device. This level of access would allow a malicious application to bypass protected data, alter security configurations, install persistent malware, interfere with other applications, or disable critical security tools. The precise impact would depend on the specific behavior of the exploited service, the device’s configuration, and any additional conditions required for successful exploitation.

No public proof-of-concept or detailed technical exploit information was included in the initial disclosure. OnePlus specifically requested that the researcher refrain from independently publishing a complete technical analysis, exploitation methods, or risk mechanisms, even after security fixes are released. The company asserted its final control over public vulnerability disclosures submitted through its security program and directed the researcher to its official security platform or HackerOne for formal submission and bounty processing.

OnePlus has indicated its intention to issue a unified public announcement and credit researchers through its security honor list once the fixes and updates are fully rolled out.

What You Should Do

  • Install Updates Immediately: Users should install OxygenOS security updates as soon as they become available. Monitor official OnePlus channels for announcements regarding affected versions and patch information.
  • Avoid Sideloading Apps: Until patches are released, refrain from installing applications from untrusted sources or unofficial app stores.
  • Review Installed Applications: Regularly review all installed applications and remove any software from unknown developers or those that seem suspicious.
  • Enterprise Administrators: Monitor managed OnePlus and OPPO devices to ensure operating system updates are applied promptly. Restrict the installation of applications from unofficial app stores across managed fleets.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Linux Kernel Flaw (CVE-2024-0001) Lets Local Users Gain Root, Escape Containers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Sauron Loader Malware Evades Detection with DLL Side-Loading
September 25, 2026
Critical WordPress Comment2Shell RCE Vulnerability CVE-2022-0215 Patched
September 25, 2026
Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization
September 25, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us