OnePlus/OPPO OxygenOS (nns.ee 24 Sep): untrusted app → root via AtlasService + olc2 HAL; still unpatched
Independent researcher Rasmus Moorats (blog.nns.ee, published 24 September 2026; The Hacker News amplify same day) chains two OxygenOS local flaws into untrusted_app → uid 0 with full Linux capabilities from a normal sideloaded APK that needs no dangerous permissions. (1) AtlasService (root binder, no caller permission check) setEvent accepts attacker-controlled values that reach audioDumpInfo’s system("chmod 777 …") path via oplus.audio.dumpinfo.type (92-byte property limit; command injection). (2) vendor.oplus.hardware.olc2 HAL doShell / doShellBlocking run arbitrary /vendor/bin/sh -c for calling uid 0, landing into vendor_qti_init_shell with an unrestricted capability bound set. PoC confirmed on OnePlus 15 (CPH2747, OxygenOS 16) after development on OnePlus 12 Pro (CPH2581). OnePlus acknowledged impact across many OnePlus and OPPO products/versions but has not published a full affected list or a fix at disclosure; disclosure timeline Apr–Sep 2026 includes a May 2026 legal-threat email from OnePlus (published by the researcher). CVE IDs were being coordinated; none assigned in the write-up. No vendor CVSS. Primary: nns.ee; wire: The Hacker News 24 Sep 2026.
- Product
- OnePlus / OPPO OxygenOS (AtlasService + olc2 vendor HAL); confirmed OnePlus 15 OxygenOS 16 / OnePlus 12 Pro
- Versions
- Confirmed: OnePlus 15 (CPH2747) OxygenOS 16; OnePlus 12 Pro (CPH2581). Vendor: many OnePlus/OPPO versions affected — full list not published. No patch listed at 24 Sep disclosure.
- Exploited in Australia?
- unknown
- Patch to
- No OEM fix published at disclosure — avoid sideloading untrusted APKs on OnePlus/OPPO; prefer Play Protect / managed app stores; watch OnePlus/OPPO security bulletins for AtlasService/olc2 fixes and apply when shipped; MDM: restrict unknown-source installs
Primary: nns.ee — Getting root on OnePlus 15 from an untrusted app (24 Sep 2026) · Vendor: Researcher write-up (OnePlus/OPPO had not shipped a public advisory at disclosure) · The Hacker News — Unpatched OnePlus flaws let installed apps gain root (24 Sep 2026)
