hacker-news · Crawled Sep 24, 2026

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Read original article ↗

AI Summary

A security researcher, Rasmus Moorats, identified two unpatched vulnerabilities in OnePlus devices running OxygenOS that can be chained to allow a locally installed Android app with no permissions to gain full root access. The first flaw is in the AtlasService, which runs as root and accepts unvalidated input from any app, enabling command injection into a restricted root environment. The second flaw leverages the olc2 hardware helper service, which executes arbitrary shell commands if the caller has root—achieved via the first flaw—granting full system-level control. As of September 24, 2026, no fix or CVE had been issued by OnePlus, and the company warned the researcher against public disclosure, citing legal consequences.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.