thehackernews.com
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A researcher exposed two unpatched vulnerabilities in OnePlus’s OxygenOS that allow a malicious app, installed without any permissions, to gain root access on a OnePlus 15 and older models. The first flaw in AtlasService lets an app invoke a debugging tool that executes arbitrary text as a system command, while the second flaw in olc2 permits any root‑level command to run with full Linux privileges. OnePlus confirmed the flaws, warned about disclosure rights, and has yet to [...]