CyberSecurityNews

OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services


Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services.

The vulnerabilities are significant because Android permission prompts normally act as a barrier between untrusted apps and sensitive device functions. A user may reasonably assume that an app requesting no permissions has limited capabilities.

However, the reported OxygenOS flaws could bypass that expectation by abusing system components already running with elevated privileges.

Researcher Rasmus Moorats submitted the findings to OnePlus, which confirmed that its security team had validated the report and scheduled remediation.

In an email dated May 20, 2026, the OnePlus Security Response Center said the issues affect “all series of OPPO terminal products with universal security risks,” indicating the underlying vulnerable components may be shared across the wider OPPO ecosystem.

OnePlus 15 Zero-Permission Flaws

The attack scenario centers on privileged OxygenOS services exposed to applications installed on the phone. If a service does not adequately enforce caller identity, signature-level permissions, or input validation, an untrusted application may send crafted requests to trigger dangerous operations.

In this case, the alleged outcome is execution of attacker-controlled code as root, Android’s most privileged account. Root access would give an attacker broad control over a device.

A malicious app could access protected data, modify security settings, install persistent components, interfere with other apps, or turn off security tools. The impact would depend on the exact service behavior, device configuration, and whether exploitation requires additional conditions.

No public proof-of-concept or technical exploit details were included in the supplied disclosure. OnePlus asked the researcher not to independently publish a complete technical analysis, exploitation method, or risk mechanism, including after security fixes have been rolled out.

The company stated that it retains final control over public vulnerability disclosures submitted through its security program. OnePlus also directed the researcher to its official security platform or HackerOne for submission and bounty processing.

The company said it plans to issue a unified public announcement and credit researchers through its security honor list once it fully releases fixes and updates.

Users should install OxygenOS security updates as soon as they become available. Until the vendor publishes affected versions and patch information, users should avoid sideloading apps from untrusted sources, review installed applications, and remove software from unknown developers.

Enterprise administrators should monitor managed OnePlus and OPPO devices for overdue operating-system updates and restrict installation from unofficial app stores.

The case highlights the risks created by privileged Android vendor services. Even when Android’s core permission model is strong, a single exposed system service can let a low-privilege app gain control far beyond the access a user intended to grant.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link