Unpatched flaws in OnePlus phones let an app take full control without asking for permissions
Researcher Rasmus Moorats has shown that a OnePlus 15 running the latest OxygenOS can be rooted by a malicious app its owner installs, even if that app asks for no special permissions. To do so, he chained two flaws in OnePlus’s own software: a system service that accepts calls from any app without checking them and a helper tool that runs commands with the highest privileges. The result is full control of the phone, with no warnings or confirmation prompts. Besides the OnePlus 15, the issue affects the OnePlus 12 Pro, OxygenOS 16 in general and some OPPO devices.
Moorats notified OnePlus on 18 April. The company confirmed the flaws in May, asked him to delay publication until 17 September and then stopped replying, so the researcher made them public on 24 September before any fix was available. The good news is that the attack requires the malicious app to already be installed on the phone, so the main defence is in the user’s hands: watching what they install and where it comes from.
Tip from Soporte Informático 360
If you have a OnePlus or OPPO phone, only install apps from Google Play, review the ones you already have and remove any you don’t use or recognise, and apply system updates as soon as the manufacturer releases the patch.
Source: The Hacker News. Summary prepared by our team for informational purposes.
IT maintenance for businesses
Preventive and corrective maintenance of your equipment to avoid downtime and extend its useful life.