Interestana
Home/News/OnePlus Android Flaws Allow Root Access Without Permissions
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

OnePlus Android Flaws Allow Root Access Without Permissions

OnePlus Android Flaws Allow Root Access Without Permissions

A critical security vulnerability has been identified in OnePlus devices running OxygenOS, allowing any installed Android application to achieve root access without requiring special permissions. This discovery was made by security researcher Rasmus Moorats, who demonstrated how two chained flaws within OnePlus's proprietary software could be exploited to gain the highest level of control over an Android phone. Root access grants an application the ability to modify system files, install unauthorized software, and potentially access sensitive user data that is normally protected by the Android operating system.

According to Moorats, the exploit is effective even on OnePlus devices running the latest version of OxygenOS. When questioned, OnePlus acknowledged the severity of the issue, confirming that the same vulnerabilities affect a significant number of its devices, as well as those manufactured by its sister company, OPPO. However, OnePlus has not yet disclosed the specific models or the exact number of devices impacted by these security flaws. The company has also not provided a timeline for when a patch will be released to address these critical vulnerabilities, leaving millions of users potentially exposed.

The implications of this exploit are far-reaching. Malicious actors could potentially develop apps that, once installed by an unsuspecting user, would silently gain root privileges. This would enable them to bypass Android's security measures, which are designed to protect user data and system integrity. Such compromised devices could be used for a variety of nefarious purposes, including data theft, installing spyware, creating botnets, or even bricking the device. The fact that no special permissions are needed for the exploit to succeed means that users would not be alerted to the malicious activity through standard Android permission prompts, making detection even more challenging.

This incident highlights ongoing challenges in mobile device security, particularly concerning manufacturer-specific software layers like OxygenOS. While Android itself has robust security features, vulnerabilities introduced in custom skins or pre-installed applications can undermine these protections. The chained nature of the exploit, where two separate flaws are combined to achieve a more severe outcome, is a common tactic employed by sophisticated attackers. The lack of immediate disclosure from OnePlus regarding affected models and a patch release schedule raises concerns about the company's responsiveness to critical security threats and the potential duration of user exposure to these risks. Users are advised to remain vigilant about the applications they install and to monitor official OnePlus channels for security updates.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next