Close Menu
NCIJ Network NCIJ Network
    What's Hot

    ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    September 24, 2026

    Bitget hit by $351.6 million breach days before 8th anniversary

    September 24, 2026

    NASA Welcomes Côte d’Ivoire as Newest Artemis Accords Signatory

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
    • Bitget hit by $351.6 million breach days before 8th anniversary
    • NASA Welcomes Côte d’Ivoire as Newest Artemis Accords Signatory
    • Petronas expands fleet with delivery of newbuilt LNG carrier
    • AI Labs Want Regulation, But Can It Be Done?
    • Australia news live: Paterson says PM’s AI hack timing not a coincidence; gen Z going without for a house | Australia news
    • Italy ministers agree to ban burqa and niqab in school and cap foreigners in class
    • Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 24, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 24, 2026Vulnerability / Mobile Security

    A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone.

    OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not said which.

    OnePlus confirmed both flaws in May. In the same reply, the company told Moorats that it alone decides when to make a flaw public and warned that publishing without its permission could result in legal liability. He published on September 24 anyway, when OnePlus had released no fix.

    OnePlus set out its position in the reply, which Moorats published in full. It said a fix was scheduled, but claimed “the exclusive final right of vulnerability disclosure,” and told him that even after a fix ships, researchers may not publish full technical details on their own.

    Cybersecurity

    The company argued that European cybersecurity rules require makers to accept and fix reports but do not allow researchers to disclose them without the maker’s consent. It warned that if he published without permission, OnePlus would “pursue relevant legal liabilities in accordance with applicable laws.”

    How the Attack Works

    Moorats found the first flaw in a OnePlus service called AtlasService, which gathers debugging data, runs as root, and accepts calls from any app without checking who is calling.

    A crafted call reaches a OnePlus debugging tool that takes the app’s text and drops it, unchecked, into a system command. That hands the app root, but only within a restricted system zone called dumpstate, which cannot do everything root normally can.

    The second flaw finishes the job. OnePlus ships another service, a hardware helper called olc2, with a command that executes any shell instruction it receives. Its only guard is that the caller must already be root, which the first flaw provides.

    This time, the command runs in a zone that grants all low-level Linux privileges, including the ability to load kernel code, giving the app control of the device at the system level.

    Who Is Affected, and What You Can Do

    The attack is local. A malicious app has to be installed and running on the phone first, so it cannot be launched over the internet. But once it is there, the app needs no permissions and shows the user no prompt, and it worked on a stock phone Moorats had not modified.

    There is no evidence that anyone has used the flaws in a real attack.

    Moorats also confirmed the attack on an older OnePlus 12 Pro, and he expects the same problem across OxygenOS 16 in general. OnePlus and OPPO build their phones on shared software, which is why OnePlus’s warning covered both.

    Cybersecurity

    As of Moorats’s disclosure, OnePlus had assigned no CVE and released no fix, and no OnePlus advisory naming the flaws could be found. Until a fix ships, the one practical defense is the thing the attack needs to get started: install apps only from sources you trust, because it cannot run without a malicious app on the phone.

    By Moorats’s account, the disclosure ran over about five months:

    • April 18, 2026: reported both flaws to OnePlus.
    • May 20: OnePlus confirmed them, claimed sole control over disclosure, and warned of legal liability if he published.
    • June 22: OnePlus gave an update on its fix and asked him to hold off, and he agreed not to publish before September 17.
    • July 20 and September 11: he asked for updates and received no reply.
    • September 24: he published.

    Separately, this is not the only recent case of an installed app reaching root on flagship Android phones.

    In August, Lukas Maar, a researcher at the security firm Calif, showed a different technique that took a no-permission app to root locked phones running the latest firmware from Samsung, Xiaomi, OPPO, OnePlus, and Realme by attacking code the makers add to Android.

    OnePlus has also been slow to answer researchers before. In 2025, Rapid7 reported a separate OxygenOS flaw that let any app read a user’s texts, and said OnePlus did not respond until the research was public.

    Android apps flaws gain installed OnePlus Permissions Root unpatched
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    Island Raises $400 Million at $6.4 Billion Valuation

    AI-Powered Campaign Targets Hundreds of Online Retailers

    Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    September 24, 2026

    Bitget hit by $351.6 million breach days before 8th anniversary

    September 24, 2026

    NASA Welcomes Côte d’Ivoire as Newest Artemis Accords Signatory

    September 24, 2026

    Petronas expands fleet with delivery of newbuilt LNG carrier

    September 24, 2026
    Latest Posts

    Spain’s Pedro Sánchez is a progressive outlier in Europe – and over Ceuta, he is being made to pay for it | Eoghan Gilmartin

    August 6, 2026

    Putin Signs Law For Russia To Regulate Crypto Exchanges

    August 6, 2026

    Canadian pleads guilty to Snowflake cloud data-theft attacks

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    September 24, 2026

    Bitget hit by $351.6 million breach days before 8th anniversary

    September 24, 2026

    NASA Welcomes Côte d’Ivoire as Newest Artemis Accords Signatory

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.