Skip to content
Temporary Root Access Exploit for OnePlus Ace 6 via CVE-2026-64560

Temporary Root Access Exploit for OnePlus Ace 6 via CVE-2026-64560

First seen 26 Sep 2026, 14:53 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 16:34 UTC
  • •CVE-2026-64560 allows temporary root access on OnePlus Ace 6.
  • •Exploit is experimental and may cause data loss or device restarts.
  • •Requires specific firmware and USB debugging enabled for execution.

A vulnerability identified as CVE-2026-64560 allows for temporary root access on the OnePlus Ace 6 through a kernel exploit. This exploit leverages a use-after-free condition in the Linux kernel's POSIX CPU timer. Users can obtain root permissions for the current boot cycle, but the access will expire upon restart. The exploit is experimental and may lead to device restarts or data loss. Users are advised to back up important data before attempting to use the exploit. The exploit requires USB debugging to be enabled and specific firmware versions to be compatible. The vulnerability affects devices running kernel version 6.6.118-android15-8. The first public proof of concept was released on August 23, 2026, following the CVE's publication on July 29, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-07-29
CVE-2026-64560 published
The vulnerability CVE-2026-64560 was officially published, detailing a use-after-free issue in the Linux kernel.
Sploitus
2026-08-23
First public PoC released
The first proof of concept for exploiting CVE-2026-64560 was made public, demonstrating the exploit's functionality.
Sploitus
2026-09-25
Exploit details published
Detailed instructions for exploiting CVE-2026-64560 on the OnePlus Ace 6 were published, including methods and requirements.
Sploitus
2026-09-26
Exploit tool released
A tool for exploiting CVE-2026-64560 was released, allowing users to gain temporary root access on compatible devices.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2026-64560 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed