Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
AI-summarised brief · reviewed before publication
A researcher exposed two unpatched vulnerabilities in OnePlus’s OxygenOS that allow a malicious app, installed without any permissions, to gain root access on a OnePlus 15 and older models. The first flaw in AtlasService lets an app invoke a debugging tool that executes arbitrary text as a system command, while the second flaw in olc2 permits any root‑level command to run with full Linux privileges. OnePlus confirmed the flaws, warned about disclosure rights, and has yet to release a fix.
💡 Why It Matters
- · The attack demonstrates that even standard, permission‑free apps can subvert Android’s security model, exposing flagship devices to full system compromise without user awareness.