A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone.
OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not said which.
OnePlus confirmed both flaws in May. In the same reply, the company told Moorats that it alone decides when to make a flaw public and warned that publishing without its permission could result in legal liability. He published on September 24 anyway, when OnePlus had released no fix.
OnePlus set out its position in the reply, which Moorats published in full. It said a fix was scheduled, but claimed "the exclusive final right of vulnerability disclosure," and told him that even after a fix ships, researchers may not publish full technical details on their own.
The company argued that European cybersecurity rules require makers to accept and fix reports but do not allow researchers to disclose them without the maker's consent. It warned that if he published without permission, OnePlus would "pursue relevant legal liabilities in accordance with applicable laws."
Moorats found the first flaw in a OnePlus service called AtlasService, which gathers debugging data, runs as root, and accepts calls from any app without checking who is calling.
A crafted call reaches a OnePlus debugging tool that takes the app's text and drops it, unchecked, into a system command.
Source link




![Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content](https://images.themorningpulse.fyi/uploads/2026/09/rss-mufvac1h-vu0lfo-media.jpg)


