OnePlus's Unpatched Root Flaw Lets Any App Take Over Your Phone
A researcher found OnePlus phones can be rooted by any app with zero permissions granted. OnePlus knew for five months and still has no fix or CVE.
Install one ordinary-looking app on a brand-new OnePlus 15, and it can quietly hand itself the keys to the entire phone. No permission pop-up, no "allow access" prompt, nothing for you to approve. A security researcher just showed exactly how, and the company has known about it since April.
How two "harmless" services turn into a master key
Estonian researcher Rasmus Moorats found the problem by poking at two background services baked into OxygenOS, OnePlus's version of Android. The first, called AtlasService, is meant to collect audio debugging data. It runs with root access, which in plain terms is the highest level of control a program can have on a phone, letting it read, change, or delete practically anything. The catch: AtlasService doesn't properly check who is calling it, so any app sitting on the phone can talk to it and get a limited foothold.
That alone isn't a full takeover. The second piece, a hardware-helper service called olc2, is supposed to only take orders from processes that are already root. But once the AtlasService flaw hands an app that initial foothold, it can turn around and use olc2 to run system commands with no further checks — and walk away with complete root access. Two services that were never meant to talk to each other, chained together, add up to a total phone takeover.
Two Android services that were never designed to work together, linked into a single chain, hand a permissionless app the same level of control as the phone's own manufacturer.
Five months of "please wait," then a public disclosure with no fix
Moorats didn't publish the moment he found the bug. He reported both flaws to OnePlus on April 18, 2026. On May 20, OnePlus wrote back confirming the issues were real — and, in the same message, told him the company alone would decide when the flaws became public, warning of legal liability if he published without permission. On June 22, OnePlus gave an update on a fix and asked him to hold off further; he agreed to stay quiet until at least September 17. He went public on September 24, past that date, with OnePlus still not having shipped a patch. There is no CVE identifier (the standard reference number used to track and look up known security flaws), no CVSS severity score, and no public security advisory from OnePlus for the flaw as of this writing.
Once an app has that level of access, the practical damage isn't hypothetical. A rooted app running silently in the background could:
- Read data from other apps that's supposed to be walled off, including messages and stored credentials
- Quietly switch off built-in security protections
- Plant components that survive a factory reset or reinstall
- Tamper with or spy on other installed apps
It's bigger than one flagship phone
This isn't only a OnePlus 15 story. In that same May email, OnePlus's own security team told Moorats the underlying issue affects "all series of OPPO terminal products with universal security risks" — an acknowledgment that the vulnerable code likely runs across the wider OPPO family too, since OnePlus and OPPO share engineering under the same parent company, BBK Electronics. That puts a much larger slice of Android devices sold worldwide in the blast radius than the headline device alone suggests.
What it means if you're buying or already own one in India
This lands squarely on Indian readers. OnePlus and OPPO are consistently among the top smartphone brands by shipment volume in India, and the OnePlus 15 has been sold hard through India's festive-season sales on Amazon and Flipkart. India also has a much higher habit of sideloading — installing APK files from outside the Play Store, whether for regional apps, cracked versions of paid software, or early-access downloads — than markets like the US or Western Europe. Since this exploit only requires getting one app installed and running on the device, that sideloading culture is exactly the kind of exposure that turns a lab demo into a real-world risk. There's also no sign yet of an advisory from CERT-In, India's national cybersecurity response agency, leaving Indian owners to rely entirely on OnePlus's own, still-pending fix.
Coordinated disclosure is supposed to be a deal: researchers hold their findings quietly, companies use that time to actually fix the bug. Here, OnePlus got five months and used part of it to remind the person who found the bug that publishing it could expose him to legal risk. Until a patch lands, the safest move for OnePlus and OPPO owners is the boring one — stick to the Play Store, skip the sideloaded APKs, and watch for a software update that actually names this fix.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0