OnePlus Threatens Researcher Over Unpatched Root Flaw
OnePlus recently received a comprehensive forensic report detailing a devastating vulnerability chain within OxygenOS. This critical flaw empowers an entirely unprivileged, standard Android application to seamlessly achieve root access without requesting a single user permission. However, instead of prioritizing a rapid remediation, the corporation ominously warned the independent researcher, Rasmus Moorats, of severe potential legal liability should he proceed with publishing the technical details.
Moorats meticulously identified two distinct architectural failures deeply embedded within proprietary OxygenOS components. The primary vulnerability afflicts AtlasService, a highly privileged system daemon responsible for telemetry and debugging. This service executes with absolute root privileges and dangerously accepts incoming Binder calls originating from any active process, entirely bypassing crucial sender validation protocols.
Exploiting AtlasService and the Hardware Daemon
By maliciously manipulating the audio diagnostic handler, a rogue application can inject its proprietary data directly into a privileged system command, thereby successfully elevating its effective User ID (UID) to 0. While the stringent Security-Enhanced Linux (SELinux) architecture temporarily constrains the process’s absolute capabilities at this initial stage, the precedent is alarming. This specific peril emanating from privileged, factory-installed OnePlus components echoes a notorious 2017 incident, wherein investigators discovered the ubiquitous EngineerMode application covertly harbored latent superuser capabilities.
The secondary phase of this sophisticated attack chain weaponizes olc2, a dedicated hardware service daemon. This component incorporates a highly perilous function designated doShell, which indiscriminately executes arbitrary commands provided the calling process has already achieved UID 0 status. Crucially, the preceding AtlasService bug perfectly satisfies this exact prerequisite. Consequently, the injected command detonates within an immensely elevated privileged context, inheriting an extensive array of formidable Linux capabilities, explicitly including CAP_SYS_MODULE, CAP_SYS_RAWIO, and CAP_SYS_PTRACE. Although SELinux remains active, the malicious application successfully breaches the fundamental confines of the standard Android security sandbox.
Zero-Click Exploitation Paradigm
Terrifyingly, executing this profound attack absolutely does not require an unlocked bootloader, a pre-existing root environment, or any explicitly granted Android permissions. The sole prerequisite is that the user inadvertently installs and launches the weaponized APK file. While Moorats did not explicitly demonstrate a direct, remote exploitation vector originating from the internet, scenarios wherein a locally installed program requires virtually zero user interaction to achieve total systemic compromise are increasingly prevalent.
The researcher formally disclosed these twin vulnerabilities to OnePlus on April 18, 2026. The corporation officially acknowledged the flaws on May 20, conceding that the vulnerabilities compromised numerous OnePlus and OPPO devices. However, they steadfastly refused to publish a comprehensive inventory of the afflicted hardware models and vulnerable firmware iterations. Concurrently, OnePlus aggressively asserted its “exclusive final right” to dictate the precise timing of any public vulnerability disclosure, simultaneously issuing a stark warning to Moorats regarding the severe legal ramifications of unauthorized publication. You can read the complete technical breakdown of the OnePlus OxygenOS root vulnerability chain on the researcher’s blog.
Disclosure, Patching, and a Pattern of Delay
Subsequently, OnePlus urgently requested a significant extension to finalize the necessary software patches. Moorats graciously consented to embargo the publication until September 17. Following repeated, unanswered inquiries regarding the patching progress on July 20 and September 11, the researcher ultimately published his comprehensive technical analysis on September 24, meticulously detailing both foundational errors and the subsequent privilege escalation chain.
At the precise moment of disclosure, the vulnerability chain remained entirely unpatched. However, the situation has since evolved. Moorats recently confirmed that OnePlus successfully neutralized both vulnerabilities on the flagship OnePlus 15 device within the OxygenOS 16.0.10.500(EX01) firmware update. Unfortunately, the remediation status for the broader ecosystem of OnePlus and OPPO devices remains dangerously ambiguous, as the manufacturer continues to withhold an official, comprehensive patching manifest.
For OnePlus, this distressing saga represents the second major controversy surrounding vulnerability disclosure within mere weeks. Earlier in September, security specialists at Doyensec publicly disclosed a critical flaw facilitating the theft of OnePlus Cloud authentication tokens via a pre-installed application, a revelation forced only after enduring nine agonizing months waiting for an official patch.
This incident forcefully underscores the catastrophic risks introduced when smartphone manufacturers inject deeply flawed proprietary code on top of the robust Android foundation. In a conceptually identical scenario last year, a severe vulnerability allowed any installed program to illicitly intercept SMS messages without ever requesting the mandatory READ_SMS permission, with researchers again citing OnePlus’s prolonged, deafening silence prior to the forced public disclosure.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.