OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
OxygenOS flaws could let zero-permission apps gain root on OnePlus and OPPO devices.
Researcher Rasmus Moorats reported two OxygenOS flaws that could let Android apps with no permissions run attacker-controlled code as root on OnePlus devices, including the OnePlus 15, by abusing exposed privileged services. In a May 20, 2026 email, OnePlus said its security team validated the issues and that they affect OPPO terminal products sharing the components. No public proof-of-concept was included, and the report does not say the bugs are being exploited. OnePlus asked that full technical details not be published and said it will credit researchers after fixes ship.