A researcher discovered two unpatched flaws in OnePlus's OxygenOS that allow installed apps to gain root access without special permissions. OnePlus confirmed the vulnerabilities affect multiple devices from OnePlus and OPPO but refused to allow disclosure, claiming exclusive control over when flaws become public. After five months without a fix, the researcher published the details on September 24, revealing how the attack chains two OnePlus services to escalate privileges to full system control.
Security researcher Rasmus Moorats discovered two critical vulnerabilities in OnePlus's OxygenOS that allow malicious apps to gain root access without permissions by exploiting flaws in AtlasService and olc2 components. After OnePlus threatened legal action to prevent disclosure, Moorats published his findings in September following months of unresponsive communication, though patches have since been released.