OnePlus OxygenOS Root Exploit: Malicious App Could Gain Root Access Without Permissions

 

Flaws in OxygenOS lets malicious Android apps gain root access without permissions

A newly published security report has revealed that a malicious app installed on a OnePlus phone could gain root access without ever asking for a single permission. The researcher behind the discovery, Rasmus Moorats, found two flaws in OxygenOS that can be chained together to break out of Android’s sandbox and take control of parts of the phone that an ordinary app should never be able to reach. According to OnePlus, the issue affects multiple OnePlus and Oppo devices across different software versions, though the company has not provided a complete list of impacted models.

What makes the findings especially concerning is how little the attack appears to require from the user. Moorats first developed the exploit on an older OnePlus 12 Pro that he had already unlocked and rooted for research purposes. He then installed the same unmodified app on a OnePlus 15 running OxygenOS 16.0.3.503. That phone had not been rooted or modified in any way, and the exploit worked on the first attempt. The attacker would still need someone to install and open the malicious app, but the app itself would not need to request any permissions.

Proof of Concept PoC of root access on OnePlus 15 by just instaling an app
The attack relies on two flaws used in sequence. The first is in AtlasService, a background service that collects diagnostic and debugging information. AtlasService runs with root privileges, but it does not properly check which app is sending it a request. Moorats found that an app could make an audio debugging tool treat part of that request as a command and run it as root. Android still limits what the resulting process can do, so the attack then turns to another OnePlus component called olc2. This service can run shell commands and checks only whether a request comes from a root process. The process created through AtlasService passes that check, allowing it to run commands with much broader control over the phone.

A detailed technical breakdown of the exploit is available in Moorats’ public write-up, which explains how the two flaws work together and includes code excerpts from the test app. The exploit worked on phones using different kernel versions, leading Moorats to suspect the flaws may extend across OxygenOS 16 more widely than initially thought.

The disclosure process was far from smooth. Moorats first reported the flaws to OnePlus on April 18 and followed up after receiving no reply. The company confirmed the flaws in a May 20 email and said fixes had been scheduled. In the same response, however, OnePlus claimed it alone could decide whether technical details were published, even after patches were released. It also argued that European cybersecurity rules did not allow publication without its consent and warned of legal action if Moorats went ahead.

OnePlus later asked for more time to prepare the fixes, and Moorats agreed not to publish before September 17. Despite that extension, his requests for updates in July and September went unanswered. He ultimately published his findings on September 24, more than five months after his initial report. He has since verified that OxygenOS 16.0.10.500(EX01) fixes both flaws on the OnePlus 15.

For OnePlus and Oppo users, the case is a reminder to keep an eye on software updates and install security patches as soon as they become available. It also highlights the tension that can arise when researchers discover serious Android sandbox escape flaws and vendors delay or dispute public disclosure. While the immediate risk requires a user to install and open a malicious app, the fact that no permissions are needed makes the exploit chain particularly notable.


OnePlus threatens security researcher with legal actions if the vulnerability is disclosed even after flaw is fixed

Tags: