<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>OxygenOS on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/oxygenos/</link><description>Recent content in OxygenOS on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 28 Sep 2026 12:43:00 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/oxygenos/index.xml" rel="self" type="application/rss+xml"/><item><title>OnePlus Left a Zero-Permission Root Bug Open for 159 Days After Threatening the Researcher</title><link>https://hackingpassion.com/oneplus-zero-permission-root-oxygenos/</link><pubDate>Mon, 28 Sep 2026 12:43:00 +0200</pubDate><guid>https://hackingpassion.com/oneplus-zero-permission-root-oxygenos/</guid><description>&lt;p>An app with zero permissions can take full control of a OnePlus phone. You install it, and it is already root. &lt;strong>OnePlus was warned in April, threatened the researcher with lawyers, and left it open for 159 days.&lt;/strong>&lt;/p>
&lt;p>You install an app. It asks for nothing on the screen, not one of the permission prompts Android puts in front of you before an app can reach your camera, your contacts or your files. And that is the app that ends up owning the phone. Not a corner of it, but the phone itself. &lt;strong>Root&lt;/strong>, the level underneath the other apps, where code can read what those apps store, load itself into the kernel, and switch off whatever might catch it.&lt;/p></description></item></channel></rss>