OnePlus 15 Root Exploit Exposes Flawed Debugging Services Across OPPO Devices

Security researcher Rasmus Moorats disclosed two unpatched flaws in OxygenOS that allow installed apps to gain root access without permissions. The exploit chains a debugging service with a hardware helper to bypass Android restrictions. OnePlus confirmed the issues affect multiple brands but withheld fixes and threatened legal action against the researcher.
Key points
- A malicious app can gain root on OnePlus 15 by chaining flaws in AtlasService and olc2.
- OnePlus confirmed the vulnerabilities affect many of its devices and all OPPO terminal products.
- Moorats reported the flaws in April 2026 but published them on September 24 without a fix.
- OnePlus claimed exclusive rights to disclosure and warned of legal liability for unauthorized publication.
- No evidence of active exploitation exists, but users should install apps only from trusted sources.
Background
This incident follows a broader trend of Android security issues, including a similar root exploit affecting Samsung and Xiaomi devices in August 2026. It also highlights ongoing tensions between researchers and manufacturers regarding disclosure timelines, echoing a 2025 case where OnePlus delayed responding to a separate OxygenOS flaw.
How outlets are covering it
The Hacker News and Cybernews emphasize the technical chain of the exploit and OnePlus's refusal to provide a fix or acknowledge researcher rights under EU regulations. Zamin.uz notes that a fix for the OnePlus 15 shipped in August via OxygenOS 16.0.10.500, though it is unclear if other affected devices received updates. Cybernews criticizes OnePlus's interpretation of EU cybersecurity rules, arguing that manufacturers must actively engage with researchers rather than unilaterally controlling disclosure.
Why it matters
The vulnerability undermines Android's permission model, allowing silent, high-privilege control of devices. It exposes risks in shared software between OnePlus and OPPO and highlights the lack of standardized, enforceable disclosure timelines for major Android manufacturers.
What to watch
OnePlus must release fixes for all affected devices and clarify which models are vulnerable. Researchers may face legal challenges if they publish details without manufacturer consent, potentially setting a precedent for vulnerability disclosure in the EU.
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions The Hacker News
- Dangerous vulnerability discovered in OnePlus and Oppo smartphones Zamin.uz
- A Serious OnePlus Security Flaw Lets Apps Root Your Phone, and It's Still Not Fixed After 6 Months Android Headlines
- OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services cybersecuritynews.com
- One bad Android app could hijack your OnePlus 15, researcher warns Cybernews
Want the full story? Read the original reporting
Read on The Hacker News