OnePlus 6 Bootloader Vulnerability Could Let Attackers Boot a Modified Image; OnePlus Promises a Fix

Advertisement
By Jagmeet Singh | Updated: 11 June 2018 20:00 IST
Highlights
  • OnePlus 6 is found to have a bootloader vulnerability
  • It lets attackers boot a modified image without unlocking the bootloader
  • OnePlus has assured a software update to fix the issue

A vulnerability has been discovered on the OnePlus 6 that allows attackers to bypass bootloader protection measures and boot a modified firmware image. The new vulnerability, which thankfully requires physical access to the device, could potentially help attackers to gain total control over a device. OnePlus has since assured the release of a software update to patch the loophole. Last year, OnePlus 3, OnePlus 3T, and OnePlus 5 were spotted with a diagnostic app that had offered a backdoor to gain root access without unlocking the bootloader. The company fixed that issue through an over-the-air (OTA) update, though it received huge criticism for silently bundling the EngineerMode app that is originally designed to help device manufacturers test hardware components.

As discovered by Edge Security President Jason Donenfeld, an attacker can boot any arbitrary modified firmware image to the OnePlus 6 without unlocking the bootloader. Just as in the case of the EngineerMode app, the attacker needs a tethered connection to a PC to pus the modified image, reports XDADevelopers. There is, however, no need to enable the USB Debugging mode to exploit the flaw. This means the attacker just needs to connect the OnePlus 6 to a PC in a default state to boot arbitrary images.

Folks at AndroidPolice have managed to verify the security loophole by easily passing a new boot image to the OnePlus 6 via fastboot protocol. It has also been found that unsupervised access to the phone for a few minutes can help grant root access to anyone.

Advertisement

OnePlus in a media statement acknowledged the issue and said: "We take security seriously at OnePlus. We are in contact with the security researcher, and a software update will be rolling out shortly."

Advertisement

 

Interestingly, this isn't the first time when a OnePlus device is found to have a bootloader vulnerability. As we mentioned, the EngineerMode app that came preloaded on OnePlus 3, OnePlus 3T, and OnePlus 5 was spotted to offer root privileges to attackers without unlocking the bootloader. The app essentially offered an adb root function to provide root access once the USB debugging is enabled. "While we don't see this as a major security issue, we understand that users may still have concerns and therefore we will remove the adb root function from the EngineerMode in an upcoming OTA," the company had said in a forum post while detailing the flaw and promising an OTA update that debuted eventually in January.

Advertisement

Late last month, OnePlus 6 was in the headlines for its Face Unlock feature reportedly being fooled by a photo. A user posted a video on Twitter that showed how the latest OnePlus flagship can apparently be fooled into getting unlocked with just an image showing the face registered on it. "We designed Face Unlock around convenience, and while we took corresponding measures to optimise its security we always recommended you use a password/PIN/fingerprint for security. For this reason, Face Unlock is not enabled for any secure apps such as banking or payments. We're constantly working to improve all of our technology, including Face Unlock," OnePlus had said while defending the Face Unlock feature that is not as secure as Apple's Face ID or Samsung's Intelligence Scan that uses dedicated hardware to enable facial recognition.

 

 
REVIEW
  • Design
  • Display
  • Software
  • Performance
  • Battery Life
  • Camera
  • Value for Money
  • Good
  • Looks great
  • Excellent performance
  • Useful software customisations
  • Bad
  • Average camera quality
  • No wireless charging or weatherproofing
 
KEY SPECS
Display 6.28-inch
Processor Qualcomm Snapdragon 845
Front Camera 16-megapixel
Rear Camera 16-megapixel + 20-megapixel
RAM 8GB
Storage 128GB
Battery Capacity 3300mAh
OS Android 8.1 Oreo
Resolution 1080x2280 pixels
NEWS
VARIANTS

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: OnePlus
Advertisement

Related Stories

Popular Mobile Brands
  1. OTT Releases of the Week: The Raja Saab, Kis Kisko Pyaar Karoon 2, Parasakthi, and More
  2. Brave Ark 2-in-1 Android PC With Snapdragon 8s Gen 3 Launched in India
  3. Poco X8 Pro Series Price, Colours Inadvertently Listed on Xiaomi's Website
  4. Google Pixel 10a Spotted in Leaked Images in These Four Colour Options
  5. WhatsApp Will Soon Let You Add a 'Close Friends' Status, Just Like Instagram
  6. Here's When the Sony WF-1000XM6 Will Be Launched Globally
  7. iPhone 18 Pro Max Leak Shows Us What to Expect In Terms of Battery Capacity
  8. Claude Opus 4.6 vs GPT-5.3-Codex: Best Agentic Coding AI Model in 2026
  9. Google's February 2026 Discover Core Update Brings These Major Changes
  1. Curiosity Rover Reconnects After Solar Conjunction, Begins Critical Organic Search on Mars
  2. Impossible Neutrino Detected on Earth May Come From an Exploding Primordial Black Hole
  3. WhatsApp Will Soon Let You Add a 'Close Friends' Status, Just Like Instagram: Report
  4. Poco X8 Pro Series Price, Colourways Inadvertently Listed on Xiaomi Website in Europe: Expected Specifications
  5. Itel A100 Confirmed to Launch in India Soon; Colourways, Battery Capacity and Durability Teased
  6. Google's February 2026 Discover Core Update to Focus on Local Content, Reduce Clickbait
  7. Apple Eyes Retail Expansion in India, New Job Listings Hint at Apple Store in Hyderabad
  8. After The Last of Us, HBO Is Adapting Baldur's Gate 3 for TV With Craig Mazin as Creator
  9. Oppo Find N6 China Launch Timeline, Durability Improvements Teased: Expected Features, Specifications
  10. GPT-5.3-Codex Released as OpenAI’s First AI Model to Assist in Its Own Development
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.