OnePlus 15 Security Flaw Could Give Malicious Apps Full Root Access Without User Permission

The company confirmed the vulnerabilities in May and was preparing a fix, but no security update was available when the findings were disclosed yet.

Advertisement
Written by Sucharita Ganguly, Edited by Rohan Pal | Updated: 29 September 2026 13:16 IST
Highlights
  • The flaws reportedly extend to some Oppo devices
  • Other OxygenOS 16 devices could also be vulnerable
  • The attack requires a malicious app to be installed locally

The vulnerabilities are said to affect the OnePlus 15 (pictured) and the older 12 Pro

OnePlus is reportedly facing a serious security issue that could allow a malicious Android app to gain root access without requesting any permissions. Ethical hacker Rasmus Moorats found two vulnerabilities that can be chained to obtain extensive control over affected devices. The flaws reportedly work on the OnePlus 15 running the latest OxygenOS and may extend to other OnePlus and Oppo phones. OnePlus confirmed the issues months ago, but had not released a fix when Moorats published his findings in September.

OnePlus Security Flaws Could Give Apps Full Device Control

According to a blog post by ethical hacker Rasmus Moorats, the two vulnerabilities can reportedly be chained to take a malicious app from having no special privileges to gaining root access on the phone. The attack is local, meaning the app must first be installed on the device, but it does not need permissions or a user prompt to escalate its access.

Advertisement

The vulnerability has reportedly been reproduced on the OnePlus 12 Pro as well as the OnePlus 15, while the researcher believes other phones running OxygenOS 16 could be vulnerable. OnePlus has also indicated that the issue may extend to some Oppo models, although the affected devices have not been identified.

The attack starts with an app that is already present on the phone. That requirement prevents a remote attack, but does not provide much protection once a malicious application has been installed. The app can reportedly operate without requesting access to sensitive permissions or displaying a prompt before attempting the privilege escalation.

Advertisement

Moorats traced the problem to two OnePlus services. One of them, AtlasService, operates with root privileges and handles debugging functions. The researcher found that applications could interact with the service without adequate checks, allowing specially crafted data to reach a system utility and trigger commands with elevated privileges.

That initial access is restricted to a system area called dumpstate. On its own, it does not provide complete control of the phone. Moorats found that another component, called olc2, could be used to take the attack further because it accepts shell commands from processes that already have root access.

Advertisement

By combining the two weaknesses, the malicious app can reportedly reach a more powerful execution environment. This provides access to low-level Linux capabilities and could allow kernel code to be loaded, giving the attacker extensive control over the device.

OnePlus was first alerted to the vulnerabilities on April 18, 2026, and confirmed the issues on May 20. The company said a fix was being prepared and later asked for the disclosure to be delayed. The researcher agreed to hold the findings until September 17, but further requests for an update on July 20 and September 11 reportedly went unanswered. The vulnerabilities were subsequently disclosed publicly on September 24, with no patch available at the time.

Advertisement

OnePlus had reportedly not assigned a CVE identifier to the vulnerabilities or published an advisory covering them at the time of disclosure. There was also no indication that the flaws had been used in attacks against users.

The immediate precaution is to be selective about which applications are installed on the phone. Since the demonstrated attack depends on a malicious app being present locally, avoiding applications from untrusted sources can prevent the exploit from getting the initial foothold it requires.

The findings are part of a wider pattern of security research targeting additional software that smartphone makers add to Android. In August, researcher Lukas Maar demonstrated a separate root-access technique involving current firmware from Samsung, Xiaomi, Oppo, OnePlus and Realme. That method also involved a permissionless application, but used different manufacturer components.

OnePlus has previously faced scrutiny over other OxygenOS vulnerabilities. Rapid7 disclosed a separate issue in 2025 that reportedly allowed applications to access users' text messages. The security firm said the company responded after the research became public.

 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Improved design and attractive colour options
  • Flawless flagship performance
  • Clean, polished, and feature-rich software
  • Exceptional battery life and charging speeds
  • Bad
  • 165Hz is not worth the lower display resolution
  • No alert slider
  • Hasselblad-exclusive features missing
  • Expensive
 
KEY SPECS
Display 6.78-inch
Processor Snapdragon 8 Elite Gen 5
Front Camera 32-megapixel
Rear Camera 50-megapixel + 50-megapixel + 50-megapixel
RAM 12GB, 16GB
Storage 256GB, 512GB
Battery Capacity 7,300mAh
OS Android 16
Resolution 1,272x2,772 pixels
NEWS

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Lumio Aura 5 With 4.5-Inch Aluminium Woofers Debuts in India: See Price
  2. Oppo K14 Plus Launched in India: Price, Specifications
  3. Pixel Buds App Update Brings Gemini Voice Controls
  4. HMD Vibe 2 Pro 5G Launched in India With 64-Megapixel Sony Camera, 6,000mAh Battery
  5. Two New The Last of Us Games Are in Early Stages of Development
  6. Flipkart Reveals Pixel 11 Series, Pixel 10a Sale Prices Ahead of Big Billion Days Sale
  7. Flipkart Big Billion Days Sale 2026: iPhone 17, iPhone 15 Deals Revealed
  8. Vivo V80 Could Be More Expensive Than Its Predecessor, Leak Suggests
  9. OnePlus 15 Root Access Flaws Could Let Apps Gain Full Device Control
  1. Coinbase Secures CFTC Clearinghouse Approval to Enable 24/7 USDC Settlement
  2. Samsung Galaxy Tab S12+, Galaxy Tab S12 Ultra Design Revealed in New Leak; Spotted in EPREL Database
  3. HMD Vibe 2 Pro 5G Launched in India With 64-Megapixel Sony Camera, 6,000mAh Battery: Price, Features
  4. Motorola Reportedly Calls Its Upcoming Wide-Folding Phone ‘Razr Flex’; Key Specifications Surface Online
  5. Bitcoin Holds Near $84,000 as Rising Yields and Oil Weigh on Market
  6. OnePlus 15 Security Flaw Could Give Malicious Apps Full Root Access Without User Permission
  7. Amazon Fire TV Stick 4K 2026 Design Renders Leaked Ahead of Launch
  8. Oppo K14 Plus Launched In India With Dimensity 7360 Max SoC, 8,000mAh Battery: Price, Specifications
  9. Lava Shark 2 Pro 5G Launched in India With 6,000mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  10. Lumio Aura 5 Launched in India With Dual 4.5-Inch Aluminium Woofers, 200W Peak Output: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.