
Here’s some scary news for OnePlus 15 owners. Apparently, if you’re running the latest OxygenOS, it can be rooted by a malicious app that the owner installs and asks for no permissions. This is according to researcher Rasmus Moorats, who exploited two flaws in the latest OxygenOS update to gain root access, the highest level of control over an Android phone.
OnePlus told Moorats that these flaws also affect many other devices from OnePlus and OPPO, but did not specify which ones. OnePlus confirmed both of these flaws back in May, and told Moorats that it alone decides when to make a flaw public and warned that publishing without its permission could result in legal liability. So, he waited until September 24th to release it, by which time OnePlus still had not fixed the flaws.
The company said a fix was scheduled, claimed the “exclusive final right of vulnerability disclosure” was theirs, and told Moorats that even after a fix ships, researchers may not publish full technical details on their own.
We won’t detail how this attack works so as not to put additional users at risk.
What you can do to protect yourself
The first thing you can do is make sure your phone is up to date, even though OnePlus hasn’t actually patched the flaws yet. Secondly, don’t install any APKs you don’t know the source of. This is the biggest way that malicious apps make their way onto phones and other devices.
The attack has also been confirmed on older OnePlus devices, including the OnePlus 12, and he suspects that the same problem exists across OxygenOS 16 in general. With OnePlus and OPPO sharing software builds across their portfolios, this is probably a flaw on a huge number of devices from both companies, as well as realme.
The biggest thing here is: why hasn’t OnePlus patched it? The flaws were reported on April 18, 2026. That’s almost six months ago now.
The post A Serious OnePlus Security Flaw Lets Apps Root Your Phone, and It’s Still Not Fixed After 6 Months appeared first on Android Headlines.