Zero-Permission App Flaw Lets Attackers Gain Root on OnePlus and Oppo Phones

Malicious Android App Could Gain Root Access on OnePlus Phones Without Permissions

A serious OxygenOS security issue allowed a malicious Android app to gain root access on a OnePlus phone without requesting any permissions. The discovery raises major concerns because Android’s permission system is designed to prevent apps from accessing sensitive parts of a device unless the user explicitly allows it.

Security researcher Rasmus Moorats uncovered two vulnerabilities in OxygenOS that, when combined, could let an app escape Android’s normal sandbox protections and execute commands with root-level privileges. According to the researcher, OnePlus confirmed that the flaws affect multiple OnePlus and Oppo devices across different software versions, although the company has not publicly shared a full list of impacted models.

The exploit was first developed on an older OnePlus 12 Pro that had already been unlocked and rooted for research purposes. However, the most alarming part came later, when the same test app was installed on a OnePlus 15 running OxygenOS 16.0.3.503. That device had not been rooted, unlocked, or modified, yet the exploit reportedly worked on the first attempt.

For the attack to succeed, a user would still need to install and open the malicious app. However, the app would not need to ask for camera, microphone, storage, location, or any other Android permissions. That makes the issue especially dangerous, since users often rely on permission prompts to judge whether an app may be risky.

The attack chain relies on two separate OxygenOS components.

The first flaw involves AtlasService, a background service used for diagnostic and debugging tasks. This service runs with root privileges, but the researcher found that it did not properly verify which app was sending requests to it. By abusing this weakness, a malicious app could cause an audio debugging tool to treat part of a request as a command and run it with root privileges.

However, Android still places some limits on what that newly created process can do. To bypass those restrictions, the exploit then uses a second OxygenOS component called olc2. This service is able to run shell commands and appears to check only whether the request comes from a root process. Because the process created through AtlasService meets that condition, it can pass the check and execute commands with much broader control over the phone.

The researcher said the exploit worked across devices using different kernel versions, suggesting the vulnerabilities may have affected a wider range of OxygenOS 16 builds. OnePlus also reportedly indicated that Oppo devices were affected, though no complete device list has been released.

Moorats first reported the vulnerabilities to OnePlus on April 18. After receiving no response, he followed up, and the company confirmed the issues in a May 20 email. OnePlus said fixes had been scheduled, but also claimed it had authority over whether technical details could be published, even after patches were released. The company also warned of possible legal action if the researcher published the findings without approval.

OnePlus later requested additional time to prepare fixes, and the researcher agreed to delay publication until September 17. He said his later requests for updates in July and September went unanswered. The findings were eventually published on September 24, more than five months after the initial report.

The good news is that the researcher has confirmed OxygenOS 16.0.10.500(EX01) fixes both vulnerabilities on the OnePlus 15. Users with OnePlus or Oppo devices should check for the latest software update as soon as possible and avoid installing apps from unknown or untrusted sources.

This incident highlights why timely security patches are critical. Even when an app asks for no permissions, flaws in system-level services can still create serious risks if attackers find a way to abuse them. For OnePlus and Oppo users, keeping OxygenOS updated is currently the most important step to reduce exposure to this root access vulnerability.