EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Fonte editoriale
Fonte OSINT editoriale. Il contenuto e un'indicazione da verificare con fonti istituzionali o tecniche indipendenti prima di decisioni operative.
Sintesi operativa EudorIA

Cosa significa

Priorità 70/100

Unpatched flaws in OnePlus 15 and other OxygenOS devices allow malicious apps to gain root access without permissions. A researcher exploited two vulnerabilities in OnePlus's software to achieve this. The attack requires local installation of a malicious app and does not spread over the internet. No real-world exploitation is known. A fix is scheduled but not yet released.

Perché conta

For Italian PMIs using OnePlus devices, this flaw allows unauthorized apps to gain full control over the device, risking data theft, system compromise, and operational disruption. The lack of a patch and public disclosure increases exposure.

Benefici operativi potenziali

  • Reduces the risk of unauthorized root access and privilege escalation
  • Limits the attack surface by controlling app installation sources
  • Improves overall device security posture through regular patching and monitoring
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiPatch managementSegmentazione di reteMonitoraggio / SIEMFirewall NGFW / IPSFormazione / awareness
DestinatariITSOCCISO
Centro informazioni

Traduzione in elaborazione

The Hacker News

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Fonte
The Hacker News
Entità pubblicatrice
The Hacker News
Tipo entità
editorial osint
Area
Global
Lingua originale
en · traduzione in preparazione
Pubblicazione
24/09/2026 20:10
Apri la fonte originale