
Unpatched OnePlus Flaws Let Any Installed Android App Gain Root
A researcher chained two flaws in OnePlus's own software to gain root on a OnePlus 15 running the latest OxygenOS, using an app that requests no permissions. OnePlus shipped no fix before the September 24 disclosure.
An app installed on a OnePlus 15 running the latest OxygenOS can take root-level control of the device without asking the owner for a single permission. Security researcher Rasmus Moorats chained two flaws in OnePlus's own software and published his findings on September 24, 2026, after the company released no fix.
OnePlus confirmed both flaws in May and told Moorats that the same issues affect many more of its devices as well as phones made by OPPO. The company has not said which models are affected.
How the flaws chain together
The first weakness sits in a OnePlus service called AtlasService, which gathers debugging data. It runs as root and accepts calls from any app without checking who is calling. A crafted call reaches a OnePlus debugging tool that inserts text supplied by the app, unchecked, into a system command.
That hands the app root, but only inside a restricted zone called dumpstate, where root cannot do everything it normally can. A second flaw finishes the job: a hardware helper service called olc2 executes any shell instruction it receives, guarded only by the requirement that the caller is already root. This time the command runs in a zone that grants all low-level Linux privileges, including loading kernel code.
A local attack, no prompts, no patch
The attack is local: a malicious app has to be installed and running on the phone first, so it cannot be launched over the internet. Once there, it asks for no permissions and shows the owner no prompt. Moorats also confirmed the chain on an older OnePlus 12 Pro and expects the same problem across OxygenOS 16.
The researcher found no evidence that anyone has exploited the flaws in a real attack. At the time of disclosure OnePlus had assigned no CVE, released no fix and published no advisory naming them. Until a patch ships, the practical defence is the step the attack depends on: install apps only from sources you trust.
Disclosure dispute and timeline
In its May reply, which Moorats published in full, OnePlus said a fix was scheduled but claimed "the exclusive final right of vulnerability disclosure" and warned of legal liability for publishing without its permission. The company argued that European rules oblige manufacturers to accept and fix reports, but do not let researchers disclose them without the maker's consent.
Moorats reported the flaws on April 18, 2026; OnePlus confirmed them on May 20, gave a fix update on June 22 and he agreed to hold publication until September 17. He asked for updates on July 20 and September 11, got no reply, and published on September 24. Earlier cases point the same way: in August, researcher Lukas Maar of the security firm Calif took a permission-free app to root on locked phones from Samsung, Xiaomi, OPPO, OnePlus and Realme.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.