Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
Positions OnePlus as responsive and transparent by highlighting its confirmation of impact while omitting timelines, root causes, or accountability for shipping vulnerable software.
View original on thehackernews.comOverview
A security researcher demonstrated a zero-permission root exploit on OnePlus 15 devices by chaining two unpatched vulnerabilities in OnePlus's proprietary software, with OnePlus confirming broader impact across its and OPPO's device lineup.
TL;DR
- Researcher Rasmus Moorats achieved full root access on OnePlus 15 without any user-granted permissions
- Exploit relies on two unpatched flaws in OnePlus's own software stack—not Android or third-party code
- OnePlus confirmed the flaws affect multiple devices across OnePlus and OPPO brands, but no patch timeline or mitigation has been disclosed
Key Stats
2
chained vulnerabilities
Both reside in OnePlus's proprietary system components
multiple
affected device families
Confirmed by OnePlus to extend beyond OnePlus 15 to other models and OPPO devices
Questions Answered
Narrative Frame
safety framing
Spin Score
60%
Emphasizes vendor cooperation and scope acknowledgment; minimizes OnePlus’s responsibility for introducing and maintaining exploitable OEM code in production devices.
What the story wants you to believe
This is a responsible disclosure event where vendor cooperation validates seriousness — not a symptom of preventable engineering or governance failure.
What it makes harder to question
Why OnePlus shipped exploitable OEM code in its latest OS release, and why no patch has been issued despite confirmed broad impact.
How the spin works
Combines attribution
Who Benefits If This Frame Spreads
OnePlus Security Response Team
Reinforces perception of proactive engagement with researchers and control over disclosure narrative
Citing vendor confirmation without quoting timelines or commitments allows framing as cooperative without exposing delays or internal failures
The Frame
Responsible disclosure partner navigating complex ecosystem constraints
Missing Context
- No disclosure date, no CVE assignment status, no statement on whether patches are in development or testing, no explanation of why these flaws persisted in latest OxygenOS
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
The article presents OnePlus’s confirmation of the flaw’s scope as evidence of responsiveness — turning a failure of secure development and timely patching into a demonstration of transparency.
- Claim
A OnePlus 15 running the latest OxygenOS can be rooted
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions.
- Frame
Blame shifts elsewhere
Responsible disclosure partner navigating complex ecosystem constraints
- Beneficiary
perception of proactive engagement with researchers and control over disclosure
OnePlus Security Response Team — Reinforces perception of proactive engagement with researchers and control over disclosure narrative
- Gap
No disclosure date, no CVE assignment status, no statement
No disclosure date, no CVE assignment status, no statement on whether patches are in development or testing, no explanation of why these flaws persisted in latest OxygenOS
- AI Risk
AI may repeat the headline as fact
Researcher found unpatched root exploit on OnePlus 15 requiring no permissions; OnePlus confirmed wider impact across its and OPPO’s devices.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. | Attributed assertion with researcher name and device/OS specificity | Claim Present in Source | High | Proof-of-concept code or video demonstration; Independent replication report; CVE identifier or NVD entry |
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions.
evidence: Attributed assertion with researcher name and device/OS specificity
"A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions."
Evidence Gaps
- Proof-of-concept code or video demonstration
- Independent replication report
- CVE identifier or NVD entry
Fact Check Signals
0 of 1 claim matched · confidence: low · checked September 25, 2026
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
The Hacker News · Media
Counter-Frames
Brand Frame
Responsible disclosure partner navigating complex ecosystem constraints
Media / Reader Counter-Frame
Framing as a systemic failure of OnePlus’s software quality control and patch discipline — not just a researcher discovery.
Regulatory Counter-Frame
Framing as a violation of implied security warranties under consumer protection laws (e.g., EU Cyber Resilience Act obligations for manufacturers).
AI Summary Frame
Omitting the OEM-specific nature of the flaws and falsely generalizing to 'Android root exploits', diluting accountability.
Questions Not Answered
- When were these flaws first reported to OnePlus?
- What specific OnePlus software components contain the flaws (e.g., preloaded services, firmware modules)?
- Has any evidence of real-world exploitation been observed?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
34
Trigger score 0
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"Researcher found unpatched root exploit on OnePlus 15 requiring no permissions; OnePlus confirmed wider impact across its and OPPO’s devices."
Concern: AI may drop the critical nuance that both flaws reside in OnePlus’s *own* software (not Android OS), misattributing responsibility to Google or generic 'Android vulnerabilities'.
-
Published
Sep 24, 2026
-
Ingested
Sep 25, 2026
-
SpinGraph Created
Sep 25, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_unpatched_oneplus_flaws_let_installed_android_ap
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from The Hacker News
View all →- Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
- Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
- FBI Seizes 7 Domains, Disrupts Flax Typhoon Tools Used in Critical Infrastructure Intrusions
- Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
- The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition
- ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO