Quick Takeaways
- A malicious app can exploit two software flaws in OnePlus devices to gain root access without permissions, potentially giving attackers full control over the device.
- The attack relies on local installation of a malicious app, which can operate silently and show no prompts, increasing the risk of undetected system compromise.
- No patch or CVE has been released yet, and the vulnerabilities affect multiple models including OxygenOS 16, highlighting an ongoing threat with no immediate fix.
Threat, Attack Techniques, and Targets
The threat involves a vulnerability in the latest OxygenOS for OnePlus 15 phones. A malicious app can gain root control without needing any permissions from the user. This is possible because of two flaws in OnePlus’s software. One flaw allows an app to call a debugging service that does not check who is making the call. This gives the app limited root access. The second flaw allows the app to run any shell command, which can include commands that load kernel code. The attacker can then take full control of the device.
The attack needs the malicious app to be installed and running on the phone first. It cannot be done directly over the internet. The attack works on stock phones without any modifications. It has been tested on both the OnePlus 15 and an older model, the OnePlus 12 Pro. Because OnePlus and OPPO use similar software, the same problem likely exists on many devices using OxygenOS 16. The attack targets Android smartphones running this vulnerable software.
Impact, Security Implications, and Remediation Guidance
The main impact is that an attacker can gain complete control over the device. This means they can access personal data, install malicious software, or take other harmful actions. Since the attack relies on a malicious app, users are at risk if they install apps from untrusted sources. Currently, there is no evidence that anyone has exploited this flaw in real-world attacks.
OnePlus has not yet released a fix or assigned a CVE number to this issue. The company has stated that a fix is scheduled but has not provided details. They also maintain that researchers should not disclose technical details without permission, which delays public awareness. Until a patch is available, users should only install apps from trusted sources.
For now, the best defense is to be cautious about what apps are installed on the device. Users should avoid installing apps from unknown sources. For complete security guidance, users should contact OnePlus or consult official security advisories.
Stay Ahead with the Latest Tech Trends
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
