OnePlus OxygenOS root exploit disclosed
Researcher Rasmus Moorats chained two unpatched OnePlus software flaws to gain root access on an Android phone via a malicious app requiring no

Researcher Rasmus Moorats has exposed a critical root exploit in OnePlus OxygenOS, chaining two vulnerabilities to gain full system control from a malicious app that requests no special permissions. He disclosed the findings on September 24, 2026, after OnePlus confirmed the flaws in May but issued no patch and warned of legal action against unauthorized publication.
The attack is local, requiring a malicious app to be installed and running on the target phone; it cannot be launched remotely over the internet. The exploit chain starts with a flaw in AtlasService, a OnePlus debugging data collector that runs with root privileges. This service accepts calls from any installed app without verifying the caller's identity. A crafted call reaches a debugging tool that drops the app's text unchecked into a system command, granting root access within a restricted zone.
A second flaw in the olc2 hardware helper service is then triggered. This service exposes a command that executes any shell instruction it receives, but its access check expects the caller to already hold root privileges. Since the first flaw grants root, the second flaw executes, running in a zone that grants all low-level Linux privileges, including the ability to load kernel code, resulting in full system control.
OnePlus acknowledges flaws but delays fix and controls disclosure
OnePlus confirmed both bugs to the researcher in May 2026. The company claimed the "exclusive final right of vulnerability disclosure," and warned that if he published without permission, OnePlus would "pursue relevant legal liabilities in accordance with applicable laws." OnePlus stated the flaws affect many more of its devices and those of its sister brand OPPO, though it did not specify which models.
The company argued that European cybersecurity rules require manufacturers to accept and fix reports but do not allow researcher disclosure without maker consent. It said a fix was scheduled, but claimed researchers may not publish full technical details even after a fix ships. As of Moorats's disclosure on September 24, 2026, OnePlus had assigned no CVE identifier, released no fix, and issued no public advisory naming the flaws.
Timeline of reporting, delay, and eventual disclosure
Moorats reported the two flaws to OnePlus on April 18, 2026. On June 22, OnePlus provided an update on a fix and asked him to hold off on publication; he agreed not to publish before September 17. Moorats requested further updates on July 20 and September 11, 2026, but received no reply from the company. With no fix released, he published his findings on September 24, 2026.
Affected devices and broader risk context
The flaws were demonstrated on a OnePlus 15 running the latest OxygenOS and confirmed on an older OnePlus 12 Pro. They are expected to affect devices across OxygenOS 16. The shared software base between OnePlus and OPPO explains why the company's warning covered both brands. There is no evidence the flaws have been used in active attacks in the wild.
This incident follows a pattern. In 2025, Rapid7 reported a separate OxygenOS flaw that allowed any app to read a user's text messages, noting that OnePlus did not respond until the research was made public. In August 2026, researcher Lukas Maar demonstrated a separate technique for escalating no-permission apps to root on locked phones by targeting manufacturer-added code in Android.
Phone makers add privileged services for debugging, hardware support, and device management. If these services lack proper caller checks or expose unsafe command interfaces, they can bypass the Android app sandbox. Device owners cannot inspect or repair these privileged services themselves. The primary defense until a fix is released is to install apps only from trusted sources, review unfamiliar packages, and install security updates when they are eventually published. Users can check the OnePlus software update page for device updates.
Possible distribution routes for a malicious app include third-party app stores, deceptive downloads, or a compromised supply chain. Until a fix ships, users should install apps only from trusted sources.





