Select a theme from the list.
Insights

From our experts

Latest
Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data TheftUnpatched OnePlus Chain Gives Permissionless Android Apps Root ControlMacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelStorm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookExploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureAI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsMicrosoft Builds an Agentic Command Center for the Modern SOCOT Segmentation Study Finds Critical Devices Sharing Networks With Everyday ITBifrost Gateway Flaw Opens AI Infrastructure to Unauthenticated Command ExecutionTrustSink Turns a Rogue MFA Provider Into a Silent Password CollectorColorado Water Attacks Show How Small Utilities Become Physical TargetsJade Sleet Turns Developer Interviews Into a Doorway to IT ProvidersStolen Ribon App Credentials Open BigCommerce Stores to Data Theft
Security Insight

Unpatched OnePlus Chain Gives Permissionless Android Apps Root Control

Unpatched OnePlus Chain Gives Permissionless Android Apps Root Control
Photo by panumas nikhomkhai on Pexels

A researcher has disclosed two unpatched flaws that can allow an installed Android application to gain root privileges on affected OnePlus devices without requesting special permissions. The attack chains weaknesses in two vendor services included with OxygenOS. OnePlus has indicated that additional OnePlus and OPPO devices may share the vulnerable software, but a complete affected-products list and public fix were unavailable at disclosure.

News Date: 2026-09-24

Two vulnerabilities in software shipped with OnePlus phones can be chained to give an ordinary installed application root-level control without requesting sensitive Android permissions. The research was demonstrated on a current OnePlus 15 running the latest available OxygenOS and was also reproduced on an older OnePlus model.

Vendor Services Create the Privilege Path

The first weakness affects AtlasService, a privileged OnePlus component used to gather debugging information. According to the researcher, the service accepts requests from applications without adequately verifying the caller. Crafted input can reach a debugging utility and become part of a system command.

This initial step provides root privileges inside a restricted security domain. Although powerful, that environment does not provide unrestricted control over the entire device. The second vulnerability removes that limitation.

A hardware-related service called olc2 contains functionality that can execute shell instructions when called by a root process. By combining the root access obtained through AtlasService with the olc2 command interface, the malicious application can move into a security context with broad low-level Linux capabilities, including the ability to load kernel code.

No Special Permissions or User Prompt

The attack is local rather than remotely triggered, meaning a malicious application must first be installed and launched. However, the application does not need to request dangerous permissions or display the usual Android authorization prompts. That characteristic could make an apparently simple application far more dangerous than its permission list suggests.

OnePlus reportedly confirmed the flaws in May 2026 and said they also affect other OnePlus and OPPO products, although it did not identify every vulnerable model. At the time of public disclosure, no CVE identifiers, detailed vendor advisory or security update addressing the chain were available. There was also no public evidence that attackers had exploited the weaknesses.

Risk Reduction Until Patches Arrive

  • Install applications only from trusted publishers and managed stores.
  • Remove sideloaded or unnecessary applications from affected devices.
  • Use mobile threat defense tools to monitor unexpected command execution.
  • Separate privileged corporate access from unmanaged mobile devices.
  • Apply vendor firmware updates as soon as a confirmed correction becomes available.

In my view, this case highlights a weakness in Android security assessments that focus too heavily on application permissions. Vendor-added system services operate outside the standard application model and can quietly introduce powerful attack paths. Enterprises should evaluate device manufacturers, update responsiveness and disclosure practices as part of mobile procurement, not merely compare hardware specifications.

Talk to our team →

Latest

Unpatched OnePlus Chain Gives Permissionless Android Apps Root ControlSep 25, 2026MacSync Turns Public iCloud Calendars Into a Hidden Malware Delivery ChannelSep 25, 2026Storm-2570 Changes Ransomware Brands but Keeps the Same Attack PlaybookSep 25, 2026Exploited F5 OAuth Flaw Opens a Direct Route Into Access InfrastructureSep 24, 2026AI Attack Crews Turn Online Stores Into Industrial Card-Skimming TargetsSep 24, 2026Microsoft Builds an Agentic Command Center for the Modern SOCSep 24, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path