OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Two unpatched OxygenOS flaws can let an installed Android app gain root access without requesting special permissions, a researcher found.

Written By
Kezia Jungco
Kezia Jungco
Sep 28, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Two unpatched OxygenOS flaws can let a malicious Android app gain root access on affected OnePlus devices without requesting special permissions.

Moorats developed the exploit on a OnePlus 12 (CPH2581), then ran the same app successfully on an unmodified OnePlus 15. A malicious app must already be installed on the phone, but once running, it can escalate from an ordinary Android app to UID 0 execution with all Linux capabilities.

Two flaws turn a no-permission app into root

Security researcher Rasmus Moorats found the two vulnerabilities in OxygenOS components AtlasService and Oplus Log Core olc2. He demonstrated how they can be chained to move an ordinary installed app from Android's restricted untrusted_app environment to highly privileged root execution.

Moorats said AtlasService runs as root and accepts calls from any process without checking the caller. An attacker-controlled value can reach the audiodumpinfo debugging service and execute commands as UID 0 inside the restricted dumpstate SELinux domain. The second flaw abuses olc2, whose doShell method accepts a UID 0 caller and can launch commands in the vendor_qti_init_shell domain with all Linux capabilities.

How the exploit chain works

  • AtlasService accepts the malicious input. The service passes attacker-controlled data into the audio debugging path without a caller permission check.
  • The app reaches restricted root. audiodumpinfo runs the injected command as UID 0 in the dumpstate domain, where SELinux still limits some actions.
  • olc2 completes the escalation. The app then calls the vendor HAL's shell function and reaches vendor_qti_init_shell, which carries all Linux capabilities.

The attack requires a malicious app on the phone

The flaws do not provide a remote attack path. A malicious app must first be installed and running on the device. Once present, however, the app does not need special Android permissions or another permission prompt before attempting the privilege escalation, The Hacker News reported. The publication said there was no evidence of real-world exploitation when the research became public.

Advertisement

Which devices are affected?

Mallory identified the tested devices as a OnePlus 15 running OxygenOS 16.0.3.503 and a OnePlus 12 Pro. It also noted that no complete affected-device list, CVE identifier, or remediation details had been published at the time.

Moorats said OnePlus told him during disclosure that the vulnerabilities affect multiple OnePlus and OPPO products across different software versions. The sources reviewed for this story do not include a complete public list of affected devices.

Researcher says disclosure began in April

Moorats said he reported the flaws to OnePlus on April 18. His timeline shows that OnePlus responded in May and provided an update on remediation efforts in June.

The researcher agreed to delay publication until at least Sept. 17 after OnePlus requested more time. He said later update requests in July and on Sept. 11 went unanswered. Moorats published his technical findings on Sept. 24, with no fix available at that point.

What OnePlus and OPPO users should do

Users concerned about exposure should avoid unfamiliar APKs and remove apps they no longer trust.

Organizations managing OnePlus or OPPO phones should consider restricting sideloading through mobile device management, reviewing installed app inventories, and watching for vendor security advisories. With no complete affected-device list available in the disclosures, security teams should not assume an untested model is unaffected.

No known exploitation has been reported. A vendor patch and a complete affected-device list remain the main items to watch.

Also read: Android users should also watch for RatHat malware, which can pose as Google Chrome, abuse Accessibility and ADB, steal credentials, and reinstall itself after removal.

Kezia Jungco

Kezia Jungco is a staff writer with five years of hands-on experience testing and analyzing generative AI platforms, chatbots, and NLP tools. She writes in-depth coverage for both enterprise and consumer audiences, focusing on artificial intelligence, data analytics, CRM solutions, cloud infrastructure, cybersecurity, and emerging tech trends. Her work appears in TechRepublic, eWEEK, Datamation, TechnologyAdvice, and Selling Signals.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.