OnePlus has released a critical security patch for OxygenOS that closes a vulnerability allowing malicious apps to take full control of your device. This update matters because the flaw lets attackers gain root access without asking for any permissions, leaving users exposed to silent data theft or remote manipulation. Anyone running older versions of the operating system on affected hardware should update immediately to close this security gap.
Critical update resolves root access vulnerability on OnePlus and Oppo devices
The vulnerability exists in the OxygenOS software layer running on OnePlus and Oppo smartphones. Security researcher Rasmus Moorats identified the issue on an older OnePlus 12 Pro and confirmed it also affects the newer OnePlus 15. The flaw allows unprivileged applications to bypass standard security restrictions and execute commands with the highest system privileges.
- Vulnerable Service: AtlasService
- Vulnerable Component: olc2
- Affected Devices: OnePlus 12 Pro, OnePlus 15
- Vulnerable OS Version: OxygenOS 16.0.3.503
- Fixed OS Version: OxygenOS 16.0.10.500(EX01)
Moorats chained two specific components to build the exploit. The first component is AtlasService, a background service that collects diagnostic data and runs with root privileges. The second component is olc2, which executes shell commands from any process running as root. The attacker only needs to trick the user into installing and opening the malicious app to trigger the chain.
OnePlus confirmed that the flaws affect multiple devices across different software versions, though the company has not released a complete list of all affected models. The vulnerability was present in OxygenOS version 16.0.3.503. The fix is available in OxygenOS 16.0.10.500(EX01), which resolves both flaws on the tested devices. Researchers suspect the issue may extend across all OxygenOS 16 versions due to kernel similarities.
The vendor initially threatened legal action regarding the disclosure but later requested an extension to prepare the fix. Moorats agreed to delay publication until September 17 to allow OnePlus time to develop the patch. The company has now released the update to address the critical security risk. Users should verify their software version and install the latest update to protect their devices.
Source: NotebookCheck




Discussion
0 comments