Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
Summary
Researchers have discovered two unpatched vulnerabilities in OnePlus devices running OxygenOS that allow installed Android apps to gain root access without requiring any special permissions. This chaining of flaws effectively grants a malicious app the highest level of control over the device, and OnePlus has acknowledged that these issues affect a wide range of their devices as well as OPPO devices.
IFF Assessment
The discovery of vulnerabilities that allow malicious apps to gain elevated privileges on user devices represents a significant threat to user data and device integrity.
Severity
This vulnerability is estimated to have a high CVSS score due to its potential for significant impact. An attacker can gain unauthorized root access, allowing them to perform any action on the device, including data theft, further malware installation, or complete device compromise, often without requiring user interaction beyond the initial app installation.
Defender Context
This discovery highlights the critical need for ongoing vigilance in patching mobile devices and the importance of comprehensive security testing for OEM-developed software. Defenders should advise users to be cautious about app installations, even from seemingly reputable sources, and monitor for official security advisories from manufacturers.