Contents

OnePlus Left a Zero-Permission Root Bug Open for 159 Days After Threatening the Researcher

 

Ethical Hacking Complete Course Zero to Expert

Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.

→ Take the full course
 
Contents

An app with zero permissions can take full control of a OnePlus phone. You install it, and it is already root. OnePlus was warned in April, threatened the researcher with lawyers, and left it open for 159 days.

You install an app. It asks for nothing on the screen, not one of the permission prompts Android puts in front of you before an app can reach your camera, your contacts or your files. And that is the app that ends up owning the phone. Not a corner of it, but the phone itself. Root, the level underneath the other apps, where code can read what those apps store, load itself into the kernel, and switch off whatever might catch it.

Normally an app cannot get near any of that. When you install one, Android keeps it walled off from the rest of the phone, in what is called the untrusted_app sandbox. It can use the camera if you allow it, read its own files, talk to a short list of system services, and little more. That is what stands between a random app and your photos, your messages and your accounts.

Root undoes it. Root is the top account on the phone, the one the system itself runs as, and it can reach anything. That is what this attack is after. OxygenOS, the version of Android OnePlus builds on, handed it over through two flaws in code the company wrote itself.

The bugs were not in Android itself. They were in the extra software OnePlus adds on top. The base of Android is picked over by a lot of eyes, so that is not where the researcher looked. He went straight for the services OnePlus bolts on, because far fewer people ever look at them, and that is exactly where both holes turned out to be. OnePlus is not alone in this. In August other researchers showed a single method that walks an ordinary app up to root across phones from several of the big Android makers, OnePlus among them. The pattern is the same each time: the phone is safer than the maker’s own additions to it.

Those flaws were found by Rasmus Moorats, who went looking for exactly this on the OnePlus 15 he carries himself. He built the working exploit on an older OnePlus 12 he kept around, so he would not have to tamper with his daily phone, then installed the same unchanged app on the 15. It worked on the first attempt.

The road to root starts with a little helper OnePlus runs in the background to collect debug and crash data. It runs as root, and it takes orders from any app on the phone without once asking who is calling. Its name is AtlasService. Any app can talk to it, and that is the way in.

One of the jobs you can hand it is a certain event. You give it a piece of text, it builds a folder path out of your text, and then it runs a command to set the permissions on that folder. The command is this:

1
system("chmod 777 " + your_text)

The problem is that the text is never checked for anything dangerous. So instead of a harmless folder name, the app sends a semicolon followed by its own command, and the phone runs that command as root. Android limits these text values to 92 bytes, which is not much room, but it is enough to tell the phone to run a script the app has already written into its own storage folder. From a single request, the app is running code as root. The researcher’s verdict on a boot service that drops an app’s text straight into a shell command in 2026 was blunt: “definitely a choice.”

That first step lands the app in a limited kind of root, a stripped-down account Android calls dumpstate. It holds the top user id, but tight rules keep it boxed in. It can read and write most of your storage and reach a long list of other system services, and one of those services is the second flaw.

The second flaw is plainer than the first, and worse. OnePlus ships another background service, this one part of the code that talks to the phone’s chips. It has a command that takes any instruction you give it and runs it. The command is literally named doShell. The researcher’s reaction when he found it was flat: “why does this even exist?” The only lock on it is a check that the caller is already root, and the first flaw had already handed that over.

What makes it dangerous is where that shell lands. It can do almost anything the Linux core allows. It can load a kernel module, a piece of code that runs inside the phone’s core, which is how a rootkit digs in and never leaves. It can reach the hardware directly, underneath the operating system. It can look inside other apps while they are running and read what they hold. This is not knocking at the edges anymore. This is inside the kernel, the core of the phone, below where security apps ever look.

Put end to end, the attack runs like this:

  • โ†’ An app with no permissions sends AtlasService a crafted event
  • โ†’ AtlasService runs the app’s text inside a shell command as root
  • โ†’ That drops the app into a restricted root shell
  • โ†’ From there it calls the doShell method on the hardware helper
  • โ†’ doShell runs its command in a shell with the full set of Linux capabilities
  • โ†’ The app now has complete control of the phone

These are the two flaws he chained, and they may not be the only ones. The same telemetry service has another function that lets an app register a callback the service then runs as root. He flagged it as a likely third hole and left it alone. One service that trusts any caller, and that is only what a single person had the time to look at.

What happened after he reported it is the part that turns a phone bug into a story about power. He sent both flaws to OnePlus on 18 April 2026. After a follow-up, OnePlus wrote back on 20 May confirming both flaws, and in the same message told him what he was and was not allowed to do with his own research.

Then came the part that reads less like a bug report and more like a threat. The company said it, and it alone, gets to decide if a flaw is ever made public. Its words: it holds “the exclusive final right of vulnerability disclosure.” Even long after a fix has gone out, it wrote, a researcher is “not entitled to independently compile and publish complete vulnerability analysis reports or technical details.”

It even waved off the European rules. EU cybersecurity law, it argued, only lets a researcher hand a bug in; it does “not grant researchers the permission to disclose unauthorised vulnerability content without prior consent from the affected enterprise.” Then came the offer: send it all again through HackerOne, wait for internal review, take a bounty, and get your name on the company’s honour list. And underneath it the line that carries the weight: publish without written permission, patched or not, and OnePlus would “pursue relevant legal liabilities in accordance with applicable laws.”

OnePlus has a public page that spells out how it wants security bugs reported. It promises to fix serious ones within 90 days. It even puts a promise in writing: a researcher who plays fair and follows the rules will not be taken to court. The letter he got leaned on that very page while threatening the one thing the page swears off.

None of this is new for OnePlus. Back in September 2025 another security firm found a different flaw, one that let any app on the phone read your text messages, including the login codes banks text you. In the public list it is CVE-2025-10184.

That firm could not even report it the normal way. OnePlus’s bounty programme came with a non-disclosure agreement it would not sign, and messages through other channels went nowhere. So it published while the flaw was still wide open. Only then did OnePlus move: the first phones got a fix on 11 October 2025, and OPPO followed a few weeks later.

For the root flaws, the timeline has a turn that most of the reporting missed. While the public story was that OnePlus had shipped no fix, the company had in fact already patched the OnePlus 15. The update, OxygenOS version 16.0.10.500, started rolling out on 18 August. Its changelog says nothing about a root escalation being closed; the only security line reads that the update “integrates the August 2026 Android security patch.” The researcher, who had agreed not to publish before 17 September, emailed on 11 September asking where things stood and got no reply. He published on 24 September, 159 days after his first report.

So the picture is split. On the OnePlus 15 the flaws were quietly closed weeks before the write-up appeared, and an owner on 16.0.10.500 or later is out of range. For the other OnePlus phones, and for the OPPO devices OnePlus itself said were affected, the company has still not named the models, given it a CVE, or put out a warning. As far as the public record shows, the flaws were never used against people before they became public.

So what do you actually do about it? If you own a OnePlus 15, this part is short. Open Settings, find your OxygenOS version, and check that it reads 16.0.10.500 or higher. If it does, this pair of flaws is already shut on your phone. If it does not, the update is sitting there waiting.

If you carry any other OnePlus, or an OPPO phone, you have no version number to check against yet, because the company never said which models it left open. So it comes back to the one thing this attack cannot skip: it only runs through an app that you install and open yourself. It cannot land on the phone on its own, and it cannot be pushed to you from far away. Someone has to talk you into installing it and running it once.

That is the part you control. Stick to the Play Store, where an app at least gets a check before it reaches you. Go slow on the files people hand you: the one from a forum, the APK off a random download site, the link in a message that says install this. That is the door this attack needs, and it is the one door you control.

When did you last check which apps on your phone can reach your files, and where each of them came from? My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.

โ†’ Join my complete ethical hacking course

Hacking is not a hobby but a way of life.

Sources:

OnePlus 15 root write-up | OnePlus Responsible Disclosure Policy | OxygenOS 16.0.10.500 release notes

 
NEWSLETTER

Stay updated

Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.

By Bulls Eye

Jolanda de koff โ€ข email โ€ข donate

My name is Jolanda de Koff and on the internet, I'm also known as Bulls Eye. Ethical Hacker, Penetration tester, Researcher, Programmer, Self Learner, and forever n00b. Not necessarily in that order. Like to make my own hacking tools and I sometimes share them with you. "You can create art & beauty with a computer and Hacking is not a hobby but a way of life ...

I โ™ฅ open-source and Linux