Skip to content
Critical Root Vulnerability in OnePlus Devices Remains Unpatched

Critical Root Vulnerability in OnePlus Devices Remains Unpatched

First seen 25 Sep 2026, 01:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 04:26 UTC
  • •OnePlus devices can be rooted by malicious apps without user permissions.
  • •Two flaws in OnePlus's software chain together to enable root access.
  • •OnePlus has not yet issued a patch or CVE for the vulnerabilities.

A security researcher discovered a critical vulnerability in OnePlus devices, including the OnePlus 15, allowing installed apps to gain root access without user permissions. The researcher, Rasmus Moorats, identified two flaws in OnePlus's custom software that enable this exploit. The first flaw, in AtlasService, allows any app to execute commands as root, while the second flaw in the olc2 service executes shell commands without adequate checks. Despite reporting the vulnerabilities five months ago, OnePlus has yet to issue a patch or assign a CVE. The flaws affect multiple OnePlus and OPPO devices running OxygenOS, with no public list of affected models provided. The exploit is local, requiring the user to install a malicious app, but poses a significant risk as it can be triggered without any special permissions or prompts.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-10
CVE-2026-82079 published
OnePlus reported a vulnerability affecting its devices, but details are limited.
Shattered
2026-09-22
CVE-2026-87902 published
Public proof-of-concept code was released for the OnePlus root vulnerability.
The Hacker News
2026-09-24
Researcher discloses vulnerabilities
Rasmus Moorats publicly disclosed the OnePlus root vulnerabilities after five months of silence from OnePlus.
Shattered
2026-09-25
OnePlus confirms vulnerabilities
OnePlus acknowledged the vulnerabilities but has not provided a patch or list of affected devices.
blog.nns.ee

More articles in this cluster (3)

Following this threat?

Track BBK Electronics and CVE-2026-82079 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed