Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
Unpatched OnePlus flaws let a no-permission Android app gain root on OxygenOS phones, with no fix released.
Researcher Rasmus Moorats disclosed two unpatched OnePlus flaws that let a locally installed Android app with no permissions gain root on a stock OnePlus 15 running the latest OxygenOS. AtlasService, running as root, accepts calls from any app and passes unsanitized input into a system command; a second service, olc2, then runs arbitrary shell commands with full low-level privileges. OnePlus confirmed both issues in May 2026, said more OnePlus and OPPO devices are affected, and had assigned no CVE or released a fix by the September 24 publication. There is no evidence of in-the-wild use.