OnePlus 15 Root Chain Needs No Permissions, and OnePlus Threatened Legal Action Over It
Security / news
OnePlus 15 Root Chain Needs No Permissions, and OnePlus Threatened Legal Action Over It
Rasmus Moorats published a two-bug chain from an unprivileged app to a root shell on September 24. OnePlus says a fix merged in July.

A sideloaded app with no permissions can become root on a OnePlus 15 (model CPH2747, OxygenOS 16 or earlier), provided the owner installs it and the phone has not received the July fix. Researcher Rasmus Moorats published the two-bug chain on September 24, along with a working APK, five months after he first reported it.
The practical instruction comes first. Moorats's post lists OxygenOS 16.0.10.500 (EX01) and later as fixed, so check the build number in Settings and install any pending update. Until then, install apps only from sources you trust, because the chain needs code running on the phone.
What the two bugs do
Moorats's write-up describes an OxygenOS telemetry service called AtlasService that accepts unauthenticated binder calls from any app. It reads a system property named oplus.audio.dumpinfo.type and builds a command of the form system("chmod 777 " + untrusted_input), so an app that controls the property controls the shell command.
That injection runs inside a root diagnostic tool, audioDumpInfo. The second bug lives in a vendor hardware abstraction layer, olc2, which exposes a doShell(String cmd) method. Its only check is whether the caller's UID is 0, and the first bug supplies exactly that. The result, per the post, is a shell holding capabilities such as CAP_SYS_MODULE and CAP_SYS_PTRACE.
Moorats reverse-engineered the chain on a OnePlus 12 Pro (CPH2581) and reports that the same build worked on the OnePlus 15 on the first attempt.

Timeline
| Date (2026) | Event |
|---|---|
| April 18 | Moorats reports the flaws to OnePlus security |
| May 20 | OnePlus threatens legal action if the research is published |
| End of July | OnePlus says the fix code was merged |
| September 24 | Moorats publishes; no CVE assigned |
| September 28 | OnePlus gives Moorats a remediation status |
The disclosure dispute
The dispute matters as much as the bug. The Hacker News reports that OnePlus claimed "the exclusive final right of vulnerability disclosure" and warned of "legal liability in accordance with applicable laws" if the work went public.
The accounts of the patch status conflict. The Hacker News described the flaws as unpatched on September 24 and said no CVE existed. On September 28, OnePlus told Moorats: "We have confirmed with the responsible team that the vulnerability is fixed in the new version. The relevant code was merged at the end of July." Merged code is not the same as a build on a phone.
Patch timing is a recurring gap: the site's coverage of Check Point's exploited VPN flaws and of SharePoint CVE-2026-65660 both turned on what shipped and when. The Hacker News also recalls that Rapid7 reported OnePlus did not respond to an earlier flaw, a 2025 report about unauthorized text message access.
Which builds are fixed
| OxygenOS branch | Fixed from |
|---|---|
| 16.0.10.x | 16.0.10.500 (EX01) |
| 16.0.5.x | 16.0.5.1200 |
| 15.0.0.x | 15.0.0.2000 |
Moorats's post says 151 devices have received the fix and 18 are pending. OnePlus told him the flaws affect many more OnePlus and OPPO devices without naming models, so the list of vulnerable phones is longer than the two he tested.
Reading the risk
There is no CVSS score to overstate here, since no CVE exists. The preconditions are real: the attacker needs an installed app, no unlocked bootloader and no permission prompt. That rules out remote drive-by exploitation and puts the risk with malicious apps that reach a phone through sideloading or a store listing.
For owners of a OnePlus 15, the step is the update. For OPPO owners, OnePlus has not said whether their models are on the fixed list, and the next thing to watch is a CVE or a vendor advisory naming them.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.