OnePlus Phones Vulnerable to SMS Theft Due to Unfixed Zero-Day Flaw

TL;DR
Security researchers Rapid7 have identified a critical Android vulnerability in OnePlus devices running OxygenOS 12 that allows malicious apps to read SMS and MMS messages without user permission, potentially bypassing multi-factor authentication and exposing sensitive data. Despite multiple attempts, OnePlus has not responded to security disclosures, leading Rapid7 to publicly disclose the flaw, which affects numerous devices and versions.
Want the full story? Read the original reporting
Read on theregister.com