Shattered Critical Root Vulnerability in OnePlus Devices Remains Unpatched
Article Content
- •OnePlus devices can be rooted by malicious apps without user permissions.
- •Two flaws in OnePlus's software chain together to enable root access.
- •OnePlus has not yet issued a patch or CVE for the vulnerabilities.
A security researcher discovered a critical vulnerability in OnePlus devices, including the OnePlus 15, allowing installed apps to gain root access without user permissions. The researcher, Rasmus Moorats, identified two flaws in OnePlus's custom software that enable this exploit. The first flaw, in AtlasService, allows any app to execute commands as root, while the second flaw in the olc2 service executes shell commands without adequate checks. Despite reporting the vulnerabilities five months ago, OnePlus has yet to issue a patch or assign a CVE. The flaws affect multiple OnePlus and OPPO devices running OxygenOS, with no public list of affected models provided. The exploit is local, requiring the user to install a malicious app, but poses a significant risk as it can be triggered without any special permissions or prompts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track BBK Electronics and CVE-2026-82079 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Nintendo Switch Vulnerability Exploited via QR Codes Nintendo has issued a security advisory regarding a vulnerability in the first-generation Switch console, identified as CVE-2026-82079. This flaw allows nearby attackers to execute unauthorized code or access console data through QR codes displayed during the 'Send to Smartphone' feature or while pairing with Mario…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…