Critical Flaw Exposes OnePlus and Oppo Phones to Root Access


A silent, zero-permission exploit chain has compromised the integrity of the software powering millions of OnePlus and Oppo smartphones. Security researcher Rasmus Moorats has disclosed a critical two-stage local privilege escalation vulnerability affecting OxygenOS and ColorOS. By chaining these two flaws, any malicious local application installed on a device can bypass Android’s security sandbox, gaining full root access (UID 0) with complete Linux capabilities.

The exploit requires no user interaction, requests no special permissions, and triggers no security prompts.

Moorats developed the exploit on a rooted OnePlus 12 Pro and successfully executed it on an unmodified OnePlus 15 running OxygenOS 16. The vulnerability highlights a persistent issue in modern Android development: OEM-specific background services, added to differentiate software or aid in diagnostics, frequently introduce severe security regressions.


The Mechanics of the Chain: From User Space to Root

The exploit operates in two distinct stages, targeting proprietary software components built into the operating system by the manufacturer.

Stage 1: Exploiting AtlasService

The first vulnerability lies within AtlasService, an OEM diagnostics background service that runs with root privileges. This service is designed to handle system diagnostics but fails to implement proper access controls.

  • The Flaw: AtlasService accepts Inter-Process Communication (IPC) calls from any application installed on the device without verifying the caller's identity or permissions.
  • The Execution: An attacker-controlled local app makes a crafted IPC call to AtlasService. This call passes unescaped input to audioDumpInfo, an internal audio debugging tool.
  • The Result: The service executes the input as a system command. This grants the attacking application root access, but with a catch: the execution is confined within the restricted dumpstate SELinux domain.

While the attacker has achieved UID 0 (root) at this stage, SELinux policies prevent them from executing arbitrary system commands or accessing sensitive user data. To bypass this barrier, the exploit requires a second stage.

Stage 2: Escaping SELinux via OplusLogCore

The second vulnerability targets olc2 (OplusLogCore), a hardware helper service designed to manage system logs.

  • The Flaw: olc2 exposes a function called doShell. This function is programmed to execute arbitrary shell commands for any caller that already possesses UID 0.
  • The Execution: Because the attacker obtained UID 0 in Stage 1, they can call doShell directly.
  • The Result: The helper service executes the command outside the restricted dumpstate SELinux domain. The attacker gains unrestricted root access with all Linux capabilities, effectively taking complete control of the device.

Disclosure Timeline and Corporate Friction

The disclosure process reveals significant friction between independent security researchers and OEM security teams. Moorats first alerted OnePlus to the vulnerabilities in early 2026, initiating a months-long exchange that ultimately ended in public disclosure.

  • April 18, 2026: Moorats privately reported both vulnerabilities to OnePlus.
  • May 20, 2026: OnePlus confirmed the flaws but asserted "exclusive final right of vulnerability disclosure." The company warned Moorats of legal liability if he published the details without their explicit consent.
  • June 22, 2026: OnePlus requested more time to develop and deploy patches. Moorats agreed to delay his public disclosure until September 17, 2026.
  • July 20 & September 11, 2026: Moorats requested status updates on the patching process. OnePlus did not respond to either inquiry.
  • September 24, 2026: Having received no response and with the agreed-upon deadline passed, Moorats publicly disclosed the technical details of the exploit chain.

This friction highlights the ongoing tension between independent researchers and hardware manufacturers. While OnePlus sought to control the narrative through legal warnings, the lack of communication during the grace period forced a public disclosure to protect end-users.


Patch Status: Who is Protected?

The security patch rollout remains fragmented across the company’s vast device portfolio.

For users of the OnePlus 15, a fix is already available. The vulnerabilities were resolved in OxygenOS version 16.0.10.500(EX01), which began rolling out in August 2026.

However, the shared codebase of OxygenOS and ColorOS means the vulnerability extends far beyond a single flagship model. This shared software architecture also exposes sister brands, including devices like the newly announced OPPO K14 Plus, to potential security risks if their specific firmware builds remain unpatched.

On September 28, 2026, OnePlus informed Moorats that 151 export models across the Oppo, Realme, and OnePlus brands under active maintenance had received patches. However, the company admitted that 18 models remain unpatched. These pending devices are scheduled to receive security updates in October 2026.

Mobile operating systems are under constant siege; even iOS has faced critical zero-day patches recently, as seen with Apple's CoreGraphics exploit. For Android OEMs, the challenge is compounded by the sheer volume of active models. While the brand prepares for next-generation hardware launches like the OnePlus 16, maintaining security updates for older and mid-range devices remains a critical bottleneck.

Users are advised to check their system settings immediately and install any pending security updates to ensure their devices are protected against this local privilege escalation chain.

By LTR

Leave a Reply

Your email address will not be published. Required fields are marked *