Rasmus Moorats discovered two unpatched vulnerabilities in OnePlus devices that allow any installed application to escalate privileges to root level without requesting special permissions from the user. The researcher successfully exploited the flaws on a OnePlus 15 running the latest OxygenOS release.
The vulnerability chain exploits weaknesses in OnePlus's proprietary software rather than the Android operating system itself. An attacker needs only to trick a user into installing a malicious app through standard channels. The app requires no special permissions declared in its manifest, making it appear benign during installation. Once installed, the application can leverage the two chained vulnerabilities to gain complete system-level control over the device.
OnePlus acknowledged that these same flaws extend beyond the OnePlus 15 to affect multiple other OnePlus models. The company also confirmed that OPPO devices, which share overlapping software components, face equivalent risk. The exact number of affected devices and OPPO product lines has not been fully disclosed publicly.
Root access on an Android device grants an attacker unrestricted control. With root privileges, malicious code can read and modify any file on the phone, including encrypted messaging app databases, banking credentials stored in password managers, and private photographs. The attacker gains access to all user data regardless of Android's sandboxing protections. System-level access also allows installation of persistent malware that survives device reboots and reinstalls.
The exploit differs from typical Android privilege escalation attacks because it bypasses Android's permission model entirely. Standard Android vulnerabilities typically require the malicious app to first request dangerous permissions that appear in permission prompts during installation. Users can see camera, location, or contact access requests and decline them. This vulnerability chain requires no such declaration, leaving users with no opportunity to see warning signs before installation.
The impact extends across OnePlus's user base, which numbers in the tens of millions globally. OnePlus phones are distributed through carrier partnerships and direct sales in Europe, North America, Asia, and other regions. OPPO's similarly large installed base compounds the exposure. Any user who installs a compromised application faces immediate risk of complete device compromise.
OnePlus has not announced a public fix or timeline for patching these vulnerabilities. Security patches typically arrive through monthly firmware updates, but the company has not confirmed whether a fix exists or when users can expect it. In the interim, OnePlus device owners should avoid installing applications from unknown sources and carefully review all app installations even from trusted stores, though this approach provides only limited protection since the vulnerability requires no special permissions.
The discovery highlights persistent security challenges in Android manufacturer customizations. While Google maintains Android's core security framework, OnePlus and other manufacturers add proprietary layers that sometimes introduce new attack surfaces. These vulnerabilities demonstrate the importance of timely disclosure and rapid patching processes for manufacturer-specific flaws that affect millions of devices globally.
