A researcher discovered two unpatched flaws in OnePlus's OxygenOS that allow installed apps to gain root access without special permissions. OnePlus confirmed the vulnerabilities affect multiple devices from OnePlus and OPPO but refused to allow disclosure, claiming exclusive control over when flaws become public. After five months without a fix, the researcher published the details on September 24, revealing how the attack chains two OnePlus services to escalate privileges to full system control.
Security researcher Rasmus Moorats discovered two critical vulnerabilities in OnePlus's OxygenOS that allow malicious apps to gain root access without permissions by exploiting flaws in AtlasService and olc2 components. After OnePlus threatened legal action to prevent disclosure, Moorats published his findings in September following months of unresponsive communication, though patches have since been released.
A researcher discovered two chained vulnerabilities in OnePlus 15 (OxygenOS 16) that allow an untrusted app to gain root access and full Linux capabilities without special permissions. The exploit chains AtlasService's unprotected setEvent binder call with a path traversal in audioDumpInfo to achieve uid 0 execution; OnePlus confirmed the issue affects multiple OnePlus and OPPO devices and has fixed it in version 16.0.10.500(EX01).