Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
What it means
Unpatched flaws in OnePlus 15 and other OxygenOS devices allow malicious apps to gain root access without permissions. A researcher exploited two vulnerabilities in OnePlus's software to achieve this. The attack requires local installation of a malicious app and does not spread over the internet. No real-world exploitation is known. A fix is scheduled but not yet released.
Why it matters
For Italian PMIs using OnePlus devices, this flaw allows unauthorized apps to gain full control over the device, risking data theft, system compromise, and operational disruption. The lack of a patch and public disclosure increases exposure.
Recommended actions
- Restrict app installations to trusted sources only
- Apply patch updates as soon as they are released by OnePlus
- Implement application whitelisting to prevent unauthorized app execution
- Enable device security features such as app permissions monitoring
- Conduct regular security audits and penetration testing for all devices
- Educate users on the risks of installing apps from untrusted sources
Potential operational benefits
- Reduces the risk of unauthorized root access and privilege escalation
- Limits the attack surface by controlling app installation sources
- Improves overall device security posture through regular patching and monitoring
Translation in progress
The official content is available in the original language. The Italian version will be published once automated checks are complete.
Text acquired from the source
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
- Source
- The Hacker News
- Publishing entity
- The Hacker News
- Entity type
- editorial osint
- Area
- Global
- Original language
- en ยท translation in preparation
- Publication
- 24/09/2026 20:10