Unpatched OnePlus Flaws Enable Root Escalation for Any Installed Android App
What Happened — Researchers identified two chained flaws in OnePlus 15 devices running OxygenOS that allow a malicious app—installed without any special permissions—to obtain root (full system) privileges. OnePlus confirmed the issues affect many of its own devices and those of OPPO, and the flaws remain unpatched.
Why It Matters for Trust & Control Assurance
- Demonstrates how a missing OS‑level access‑control safeguard can let any app bypass least‑privilege principles, a scenario continuous control‑assurance programs are built to detect and evidence.
- Highlights the need for ongoing verification that mobile‑device configurations remain aligned with your organization’s access‑control policies and that patch evidence is continuously collected.
- Directly ties to Verisq’s Access Controls capability, which provides automated evidence of OS hardening, privileged‑access monitoring, and remediation tracking across device fleets.
Who Is Affected
- Mobile‑device manufacturers (OnePlus, OPPO) and their end‑user base.
- Enterprises that allow BYOD or manage corporate‑issued Android phones.
Recommended Actions
- Verify OS version and patch level on all OnePlus/OPPO devices; prioritize immediate update once a fix is released.
- Enforce mobile‑device management (MDM) policies that block installation of unsigned apps and monitor for privilege‑escalation attempts.
- Capture and retain evidence of device compliance (OS version, security‑patch status) in a continuous audit repository.
- Conduct a rapid risk assessment of any apps that could exploit the flaw and remediate or quarantine them.
Source: The Hacker News
Technical Notes
- The exploit chains two separate software defects in OxygenOS to bypass the Android permission model and gain root.
- No CVE identifier has been assigned yet; OnePlus has acknowledged the issue but has not released a patch at time of reporting.
- Impact: potential full device takeover, data exfiltration, and persistence.
Source: The Hacker News