Unpatched OnePlus services enable local root chain on OxygenOS

A chained pair of unpatched flaws in OnePlus software can allow a malicious Android app to obtain full root control on a stock OnePlus 15 running the latest OxygenOS. Researcher Rasmus Moorats reported that the app requires no special permissions and displays no user prompt, although it must first be installed and running on the device.
Moorats confirmed the attack on an older OnePlus 12 Pro as well and expects the issue to affect OxygenOS 16 more broadly. OnePlus told him that the same flaws affect additional OnePlus devices and OPPO devices, but it has not identified the affected models publicly.
Two privileged services form the chain
The first issue is in AtlasService, a OnePlus service used to collect debugging data. AtlasService runs as root and accepts calls from any app without validating the calling application. A crafted request can reach a OnePlus debugging tool that places app-supplied text into a system command without checks.
That step gives the malicious app root access only in the restricted dumpstate system domain. The restriction prevents it from exercising the full range of capabilities normally associated with root access, so the first flaw alone does not deliver complete device control.
The second issue involves olc2, a OnePlus hardware-helper service. It includes a command that executes shell instructions it receives. Its stated safeguard is that the caller must already be root, a condition supplied by the AtlasService issue. The command then runs in a domain with low-level Linux privileges, including the ability to load kernel code, enabling system-level control of the device.
Disclosure and patch status
Moorats reported both issues to OnePlus on April 18, 2026. OnePlus confirmed them on May 20 and said that a fix was scheduled. In the same response, the company asserted that it had the exclusive final right to decide when vulnerabilities could be disclosed and warned that publication without its permission could create legal liability.
On June 22, OnePlus supplied an update on the planned fix and asked Moorats to delay publication; he agreed not to publish before September 17. Requests for updates on July 20 and September 11 received no response, and he published the technical details on September 24.
At the time of disclosure, OnePlus had not released a fix, assigned a CVE, or published an advisory naming the flaws. Moorats said there was no evidence that the chain had been used in real-world attacks. The attack is local rather than remotely initiated, which means a malicious application must already be present on the handset.
What organisations and users can do now
The immediate risk is tied to software installation rather than a network-facing entry point. Because the chain starts only after an attacker-controlled app runs on the phone, users should install Android applications only from sources they trust and organisations should reinforce approved-app policies on managed OnePlus and OPPO devices until vendor fixes are available.
Teams that permit these devices should also track OnePlus advisories, identify models using affected OxygenOS releases, and be prepared to deploy updates promptly. In practical terms, restricting untrusted app installation is the available control while the underlying privileged-service flaws remain unpatched.

