ANDROID OnePlus patch closes OxygenOS flaw letting apps gain root without permissions INTEL ERYING brings Intel Raptor Lake embedded CPUs to desktop motherboards, starting at $180 GAMES Daggerfall Enhanced mod brings 24/7 shops and MMO-style multiplayer to 1992 classic GAMES EA Sports FC 27 patch 1.0.1 increases active defense sprint speed and player fatigue impact GAMES The Expanse: Osiris Reborn set for Q2 2027 release as Owlcat Games shares new visuals GAMES American Truck Simulator adds Coach Mode and Car Mode with Road Trip: Ford expansion GAMES Minecraft Adds More Than 300,000 New Players Every Day GAMES Activists urge Marvel Rivals boycott over missing hate speech reporting tool GAMES Blizzard’s Diablo IV Season 15 apology letter contained a bug that blocked compensation PC HARDWARE Noctua partners with Forced Physics to adapt 2000W server cooling for desktop PCs GAMES CD Projekt RED Marks Third Anniversary of Cyberpunk 2077: Phantom Liberty Expansion GAMES Genshin Impact update 7.1 fixes story-blocking Koholazaur bug and UI errors GAMES Minecraft Gets First New Dimension in 15 Years, Ice Caves Biome and Frozen Zombies Revealed SOFTWARE AND UPDATES Antares AutoTune Advanced launches with sub-1 ms latency and new vibrato engine

OnePlus patch closes OxygenOS flaw letting apps gain root without permissions

Daniel Cross 0 comments 2 min read

OnePlus released a critical patch for OxygenOS closing a vulnerability that allowed malicious apps to gain root access without permissions on multiple devices.

OnePlus patch closes OxygenOS flaw letting apps gain root without permissions
ANDROID

OnePlus has released a critical security patch for OxygenOS that closes a vulnerability allowing malicious apps to take full control of your device. This update matters because the flaw lets attackers gain root access without asking for any permissions, leaving users exposed to silent data theft or remote manipulation. Anyone running older versions of the operating system on affected hardware should update immediately to close this security gap.

Critical update resolves root access vulnerability on OnePlus and Oppo devices

The vulnerability exists in the OxygenOS software layer running on OnePlus and Oppo smartphones. Security researcher Rasmus Moorats identified the issue on an older OnePlus 12 Pro and confirmed it also affects the newer OnePlus 15. The flaw allows unprivileged applications to bypass standard security restrictions and execute commands with the highest system privileges.

  • Vulnerable Service: AtlasService
  • Vulnerable Component: olc2
  • Affected Devices: OnePlus 12 Pro, OnePlus 15
  • Vulnerable OS Version: OxygenOS 16.0.3.503
  • Fixed OS Version: OxygenOS 16.0.10.500(EX01)

Moorats chained two specific components to build the exploit. The first component is AtlasService, a background service that collects diagnostic data and runs with root privileges. The second component is olc2, which executes shell commands from any process running as root. The attacker only needs to trick the user into installing and opening the malicious app to trigger the chain.

OnePlus confirmed that the flaws affect multiple devices across different software versions, though the company has not released a complete list of all affected models. The vulnerability was present in OxygenOS version 16.0.3.503. The fix is available in OxygenOS 16.0.10.500(EX01), which resolves both flaws on the tested devices. Researchers suspect the issue may extend across all OxygenOS 16 versions due to kernel similarities.

The vendor initially threatened legal action regarding the disclosure but later requested an extension to prepare the fix. Moorats agreed to delay publication until September 17 to allow OnePlus time to develop the patch. The company has now released the update to address the critical security risk. Users should verify their software version and install the latest update to protect their devices.

Source: NotebookCheck

Discussion

0 comments

Leave a comment