Five months, two flaws, no fix: an app with no permissions can own a OnePlus phone
Five months and six days. That is how long Rasmus Moorats sat on what he had found in OnePlus phones, and there is still no fix for it.
He reported two flaws on 18 April. OnePlus confirmed both on 20 May, and in the same reply told him the company alone decides when a flaw becomes public and that publishing without permission could carry legal liability. In June it asked him to hold until 17 September and he agreed. He wrote again on 20 July and on 11 September and heard nothing. He published on 24 September. No CVE number, no advisory, no patch.
The flaws sit in OnePlus's own software rather than in Android. A debugging service called AtlasService runs as root and takes calls from any app without checking who is asking; hand it the right text and that text goes straight into a system command. That gets an app root, but inside a restricted zone. A second service, a hardware helper called olc2, runs whatever shell command it is given so long as the caller is already root, and it runs it with full low-level Linux privileges, kernel code loading included. Chained together, an app you installed that asked for no permissions and showed you no prompt ends up owning the phone. Moorats confirmed it on a OnePlus 15 running current OxygenOS and on an older OnePlus 12 Pro, and expects OxygenOS 16 broadly. OnePlus told him OPPO devices are affected too, without saying which ones.
Nobody has been caught using this. It also needs one thing you control completely: a malicious app actually on the phone. That means sideloaded APK files and store pages you arrived at through an advert rather than through the Play Store itself. Tendvane's network scan at least shows you every device on your home Wi-Fi, phones included, so you know what is sitting on it.