A researcher chained two flaws in OnePlus software to let a no-permission malicious app gain root on a OnePlus 15 and other affected devices. OnePlus said the issues also affect some OPPO devices, but had not released a fix before the disclosure and no evidence of real-world exploitation has been found. #OnePlus #OxygenOS #OPPO #AtlasService #olc2
Keypoints
- A malicious app can gain root on OnePlus devices without requesting special permissions.
- The attack chains flaws in OnePlusβs AtlasService and olc2 services.
- OnePlus said the issues may affect more of its own devices and some OPPO phones.
- The attack is local and requires a malicious app to already be installed on the phone.
- No fix, CVE, or official advisory was available when the disclosure was published.
Read More: https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html