Unpatched OnePlus Bugs Let Malicious Apps Gain Root Access Without Warning
A researcher has disclosed two chained vulnerabilities in OnePlus's OxygenOS software that allow a malicious app, once installed on the device, to gain root access, the highest level of control over an Android phone, without asking the user for any special permissions or showing a prompt.
The first flaw sits in a OnePlus debugging service called AtlasService, which runs as root and accepts commands from any app without verifying the caller. This lets a crafted app gain limited root access. The second flaw, in a hardware helper service called olc2, allows any command to run once the caller already has root, and grants far broader system level control, including the ability to load kernel code. Combined, the two bugs give an installed app full control of the device.
OnePlus confirmed the flaws in May and told the researcher, Rasmus Moorats, that the same issues likely affect many more OnePlus and OPPO devices, though it has not specified which models. The company also asserted it alone controls when details are published and warned of possible legal action, but Moorats released his findings publicly on September 24 with no fix yet available. There is no evidence the flaws have been exploited in real attacks, and the attack requires a malicious app to already be installed on the device rather than being exploitable remotely.