Find notable cyber news and cases, enriched with sources, timelines, and signals.

OnePlus OxygenOS local privilege-escalation flaws security flaw

Vulnerability
First reported
Last updated
Happening score
H score 26
1 unique sources, 1 articles

Summary

Hide ▲

Unpatched OnePlus OxygenOS local privilege-escalation flaws let a malicious no-permission app gain root on affected phones. The chain uses AtlasService and olc2 to move from an installed app to system-level control. OnePlus had not released a fix at disclosure time, and the issue may extend beyond the OnePlus 15 to other OnePlus and OPPO devices.

Related Happenings

Unisoc modem firmware VoLTE privilege-escalation flaw (CWE-1189)

Vulnerability
H score28 First: 17.08.2026 13:52 Last: 17.08.2026 13:52 Sources 1

About this happening: Researchers published a CWE-1189 privilege-escalation flaw in Unisoc modem firmware that can elevate modem-level access to full Android kernel control through a VoLT...

Grandstream GXP1600 series unauthenticated stack-based buffer overflow remote code execution flaw (CVE-2026-2329)

Vulnerability
H score37 First: 18.02.2026 18:35 Last: 18.02.2026 18:35 Sources 1

About this happening: The Grandstream GXP1600 series has a critical CVE-2026-2329 stack-based buffer overflow that can enable unauthenticated remote code execution on susceptible VoIP phone...

Timeline

  1. 24.09.2026 21:10 2 articles · 3h ago

    Moorats publishes the chained OnePlus root flaws

    Technical Analysis Update

    On September 24, 2026, Moorats publishes the chained OnePlus flaws that let a malicious app already installed on a OnePlus 15 running the latest OxygenOS gain root through AtlasService and olc2; he also says the same problem applies to an older OnePlus 12 Pro and likely affects OxygenOS 16 more broadly, while OnePlus still has no fix.

    Show sources