The record
Written by software from the 1 report below. The points restate them; where one says why it matters, that is Prism's reading, not a reported fact.
- A researcher discovered two vulnerabilities in the OxygenOS software used by OnePlus and OPPO devices that enable installed apps to bypass security and obtain root control.
- The exploit requires no special permissions and can be executed by a malicious app without notifying the phone owner.
- OnePlus acknowledged the flaws but has not yet provided a software fix to address the security gap.
- Users are advised to only install applications from trusted sources to mitigate the risk until a patch is released.
What to watch next
- Release of a software fix by OnePlus and OPPO
- Official CVE assignment for the identified flaws
- Potential legal action against the researcher for unauthorized disclosure
Who said what2
Only words found exactly in the article are shown, attributed and linked to the line they came from.
OnePlus
2 quotes · 1 outlet
“the exclusive final right of vulnerability disclosure”
In the article
…result in legal liability. He published on September 24 anyway, when OnePlus had released no fix. OnePlus set out its position in the reply, which Moorats published in full. It said a fix was scheduled, but claimed " the exclusive final right of vulnerability disclosure ," and told him that even after a fix ships, researchers may not publish full technical details on their own. The company argued that European cybersecurity rules require makers to accept and fix reports but do not…
“pursue relevant legal liabilities in accordance with applicable laws.”
In the article
…that European cybersecurity rules require makers to accept and fix reports but do not allow researchers to disclose them without the maker's consent. It warned that if he published without permission, OnePlus would " pursue relevant legal liabilities in accordance with applicable laws. " How the Attack Works Moorats found the first flaw in a OnePlus service called AtlasService, which gathers debugging data, runs as root, and accepts calls from any app without checking who is calling. A crafted call…
Coverage1
All filed from India
Named China · OnePlus · Oppo · Realme · Samsung · Xiaomi · Calif · Lukas Maar · Rapid7 · Rasmus Moorats
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the reports above, or say they can't.
