Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
OnePlus Vulnerabilities Allow Root Access via OxygenOS

OnePlus Vulnerabilities Allow Root Access via OxygenOS

Posted on September 25, 2026 By CWS

Recent findings have unveiled two critical security vulnerabilities within the latest build of OxygenOS, potentially allowing malicious applications to achieve root access on OnePlus devices, including the OnePlus 15. These flaws exploit privileged services in the operating system, posing a significant risk to user security.

Understanding the Gravity of the Flaws

Typically, Android’s permission prompts serve as a robust defense mechanism, distinguishing untrusted apps from crucial device functionalities. Users often feel secure when an app requests no permissions. However, the identified vulnerabilities in OxygenOS undermine this trust, enabling unauthorized access to system components with elevated privileges.

Security researcher Rasmus Moorats brought these concerns to OnePlus’s attention. The company acknowledged the validity of the report, indicating that its security team is actively working on remediation strategies. An email from May 20, 2026, from the OnePlus Security Response Center highlighted that these issues affect a broad range of OPPO products, suggesting shared vulnerabilities across the OPPO ecosystem.

Implications of Zero-Permission Vulnerabilities

The crux of the threat lies in the exposure of privileged OxygenOS services to apps installed on the device. If these services lack stringent enforcement of caller identity and input validation, malicious applications could potentially execute harmful operations with root-level access, Android’s highest privilege level.

This unauthorized root access could enable attackers to manipulate protected data, alter security settings, install persistent software, disrupt other applications, or disable security tools. The severity of the impact hinges on service behavior, device configuration, and any additional conditions necessary for exploitation.

While no public proof-of-concept or exploit details are currently available, OnePlus has requested that the researcher refrain from publishing a comprehensive technical analysis or exploitation methods, even after the security patches are released.

OnePlus’s Response and Recommendations

OnePlus has emphasized its control over the public disclosure of vulnerabilities through its security program. The company plans to announce unified updates and credit the researchers upon the complete release of fixes. Users are strongly advised to install OxygenOS security updates promptly.

In the interim, individuals should avoid downloading apps from untrusted sources, routinely review installed applications, and remove any unfamiliar software. Enterprise administrators managing OnePlus and OPPO devices should ensure timely application of operating-system updates and restrict app installations from unofficial sources.

This situation underscores the inherent risks associated with privileged Android vendor services. Even with a robust permission model, a single exposed system service can allow low-privilege apps to gain unintended control, highlighting the importance of vigilant security practices and timely updates.

Cyber Security News Tags:Android security, Cybersecurity, malicious apps, mobile security, OnePlus, OnePlus 15, OPPO, OxygenOS, root access, security patches, smartphone security, software update, tech news, Vulnerabilities

Post navigation

Previous Post: PamStealer Malware Evasive Tactics on macOS
Next Post: Linux Kernel Vulnerability Allows Root Access and Container Escape

Related Posts

Apple’s ‘Hide My Email’ Flaw Exposes User Addresses Apple’s ‘Hide My Email’ Flaw Exposes User Addresses Cyber Security News
Critical Flaw in Trivy Scanner Added to CISA’s Vulnerability List Critical Flaw in Trivy Scanner Added to CISA’s Vulnerability List Cyber Security News
Critical Flaw in Google Cloud Vertex AI Exposes Data Critical Flaw in Google Cloud Vertex AI Exposes Data Cyber Security News
Windows Shortcuts Exploit PowerShell for Remote Attacks Windows Shortcuts Exploit PowerShell for Remote Attacks Cyber Security News
Gmail to Drop POP3 mail Fetching to Collect Mail from other Email Accounts Gmail to Drop POP3 mail Fetching to Collect Mail from other Email Accounts Cyber Security News
What Is Out-of-Bounds Read and Write Vulnerability? What Is Out-of-Bounds Read and Write Vulnerability? Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark