OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
Brief
Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services.
The vulnerabilities are significant because Android permission prompts normally act as a barrier between untrusted apps and sensitive device functions. A user may reasonably assume that an app requesting no permissions has limited capabilities.
However, the reported OxygenOS flaws could bypass that expectation by abusing system components already running with elevated privileges.
Researcher Rasmus Moorats submitted the findings to OnePlus, which confirmed that its security team had validated the report and scheduled remediation.
