Vulnerability
Published 2026-09-24
Verified 2026-09-27

OnePlus/OPPO OxygenOS (nns.ee 24 Sep): untrusted app → root via AtlasService + olc2 HAL; still unpatched

Independent researcher Rasmus Moorats (blog.nns.ee, published 24 September 2026; The Hacker News amplify same day) chains two OxygenOS local flaws into untrusted_app → uid 0 with full Linux capabilities from a normal sideloaded APK that needs no dangerous permissions. (1) AtlasService (root binder, no caller permission check) setEvent accepts attacker-controlled values that reach audioDumpInfo’s system("chmod 777 …") path via oplus.audio.dumpinfo.type (92-byte property limit; command injection). (2) vendor.oplus.hardware.olc2 HAL doShell / doShellBlocking run arbitrary /vendor/bin/sh -c for calling uid 0, landing into vendor_qti_init_shell with an unrestricted capability bound set. PoC confirmed on OnePlus 15 (CPH2747, OxygenOS 16) after development on OnePlus 12 Pro (CPH2581). OnePlus acknowledged impact across many OnePlus and OPPO products/versions but has not published a full affected list or a fix at disclosure; disclosure timeline Apr–Sep 2026 includes a May 2026 legal-threat email from OnePlus (published by the researcher). CVE IDs were being coordinated; none assigned in the write-up. No vendor CVSS. Primary: nns.ee; wire: The Hacker News 24 Sep 2026.

Product
OnePlus / OPPO OxygenOS (AtlasService + olc2 vendor HAL); confirmed OnePlus 15 OxygenOS 16 / OnePlus 12 Pro
Versions
Confirmed: OnePlus 15 (CPH2747) OxygenOS 16; OnePlus 12 Pro (CPH2581). Vendor: many OnePlus/OPPO versions affected — full list not published. No patch listed at 24 Sep disclosure.
Exploited in Australia?
unknown
Patch to
No OEM fix published at disclosure — avoid sideloading untrusted APKs on OnePlus/OPPO; prefer Play Protect / managed app stores; watch OnePlus/OPPO security bulletins for AtlasService/olc2 fixes and apply when shipped; MDM: restrict unknown-source installs

Primary: nns.ee — Getting root on OnePlus 15 from an untrusted app (24 Sep 2026) · Vendor: Researcher write-up (OnePlus/OPPO had not shipped a public advisory at disclosure) · The Hacker News — Unpatched OnePlus flaws let installed apps gain root (24 Sep 2026)

vulnerabilities