Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Swati KhandelwalSep 24, 2026Vulnerability / Mobile Security

A recent security flaw has been discovered in OnePlus devices running OxygenOS, allowing a malicious app to gain root access without requiring any special permissions. Security researcher Rasmus Moorats identified and exploited two vulnerabilities within OnePlus’s software to achieve root access on a OnePlus 15.

OnePlus has acknowledged that these vulnerabilities also affect other devices in its lineup as well as those of OPPO, although specific models have not been disclosed.

Despite OnePlus confirming the flaws in May, no fix had been released by September 24 when Moorats decided to publish his findings. OnePlus had warned him against disclosing the vulnerabilities without permission, citing legal consequences.

The first flaw exploited by Moorats involves a OnePlus service called AtlasService, while the second flaw targets a hardware helper service called olc2. By exploiting these flaws, a malicious app could gain system-level control over the device.

It is important to note that the attack requires the installation of a malicious app on the device, making it a local threat rather than a remote one. Users are advised to only install apps from trusted sources to mitigate the risk of such attacks.

Timeline of Disclosure:

  • April 18, 2026: Flaws reported to OnePlus.
  • May 20: OnePlus confirms flaws and asserts control over disclosure.
  • June 22: OnePlus provides an update on the fix timeline.
  • September 24: Moorats publishes his findings.

Additionally, this incident is not isolated, as similar vulnerabilities have been reported in flagship Android devices from other manufacturers. It is crucial for device makers to prioritize security and promptly address such issues to safeguard user data and privacy.