Threat Intelligence

Unpatched OnePlus Bugs Let Malicious Apps Gain Root Access Without Warning

The Hacker News · 25 Sept 2026
Key Takeaway Australian small businesses using OnePlus or OPPO Android devices should restrict app installations to trusted sources and apply security updates immediately once OnePlus releases a fix.

A researcher has disclosed two chained vulnerabilities in OnePlus's OxygenOS software that allow a malicious app, once installed on the device, to gain root access, the highest level of control over an Android phone, without asking the user for any special permissions or showing a prompt.

The first flaw sits in a OnePlus debugging service called AtlasService, which runs as root and accepts commands from any app without verifying the caller. This lets a crafted app gain limited root access. The second flaw, in a hardware helper service called olc2, allows any command to run once the caller already has root, and grants far broader system level control, including the ability to load kernel code. Combined, the two bugs give an installed app full control of the device.

OnePlus confirmed the flaws in May and told the researcher, Rasmus Moorats, that the same issues likely affect many more OnePlus and OPPO devices, though it has not specified which models. The company also asserted it alone controls when details are published and warned of possible legal action, but Moorats released his findings publicly on September 24 with no fix yet available. There is no evidence the flaws have been exploited in real attacks, and the attack requires a malicious app to already be installed on the device rather than being exploitable remotely.

Android OnePlus vulnerability root access mobile security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.