"the exclusive final right of vulnerability disclosure," OnePlus wrote to the researcher who found two flaws that let an installed app gain root on current OxygenOS phones — and warned that publishing without the company's permission could create legal liability.
OnePlus's response and its position on disclosure
OnePlus confirmed both flaws to researcher Rasmus Moorats in May and, in the same reply Moorats published, said it alone decides when to make a flaw public. The company told Moorats a fix was scheduled but also argued that European cybersecurity rules require vendors to accept and fix reports while not permitting researchers to disclose details without the maker's consent. OnePlus warned that publishing without permission would lead it to "pursue relevant legal liabilities in accordance with applicable laws." As of Moorats's public disclosure on September 24, OnePlus had assigned no CVE, released no fix, and had issued no advisory naming the flaws; the company also said the same flaws affect many more OnePlus devices and those of OPPO, though it did not name which models.
AtlasService: the first flaw that grants partial root
Moorats discovered the first vulnerability in a OnePlus service called AtlasService. According to his write-up, AtlasService gathers debugging data, runs as root, and accepts calls from any app without checking the caller's identity. A crafted call reaches a OnePlus debugging tool that takes the app's text and drops it, unchecked, into a system command. That chain hands the calling app root privileges, but only within a restricted system zone called dumpstate — a powerful escalation, but not yet full system control.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildolc2 hardware helper: the second flaw that completes the compromise
The second flaw hinges on a hardware helper shipped by OnePlus named olc2. Moorats says olc2 exposes a command that executes any shell instruction it receives; its only check is that the caller must already be root. The partial root obtained through AtlasService satisfies that check, and olc2's command runs in a zone that grants all low-level Linux privileges, including the ability to load kernel code. Together, the two flaws enable an installed app — one that asks for no special permissions and shows no prompt — to gain system-level control of a phone.
Who is affected, and what users can do
Moorats showed the technique on a OnePlus 15 running the latest OxygenOS and confirmed it on an older OnePlus 12 Pro; he expects the same problem across OxygenOS 16. The attack is local: a malicious app must be installed and running on the phone for the exploit to start, so it cannot be launched over the internet. Because the exploit requires no permissions and reveals no prompts, a stock, unmodified phone is vulnerable once such an app is installed. Moorats said there is no evidence anyone has used the flaws in a real attack. Until a vendor fix ships, the practical defense he recommends is the simple one the attack depends on: install apps only from sources you trust, because the chain cannot run without a malicious app on the phone.
Timeline, precedent, and related research
- April 18, 2026: Moorats reported both flaws to OnePlus.
- May 20, 2026: OnePlus confirmed the flaws and asserted sole control over disclosure, warning of legal consequences.
- June 22, 2026: OnePlus provided an update on its fix and asked Moorats to hold publication; he agreed not to publish before September 17.
- July 20 and September 11, 2026: Moorats requested updates and says he received no reply.
- September 24, 2026: Moorats published his findings.
The disclosure follows other recent demonstrations that no-permission apps can reach root on flagship devices. In August, Lukas Maar of the security firm Calif published a different technique that took a no-permission app to root on locked phones running the latest firmware from Samsung, Xiaomi, OPPO, OnePlus, and Realme by attacking vendor-added code. OnePlus has also been slow to answer researchers before: Rapid7 reported a separate OxygenOS flaw in 2025 that let any app read a user's texts and said OnePlus did not respond until the research was public.
These facts leave a compact but consequential set of realities: the vulnerability chain is vendor-supplied, requires only a locally installed app that asks for no permissions, and — by Moorats's tests — affects recent OnePlus models built on OxygenOS 16 and likely more devices shared across OnePlus and OPPO. The company says a fix is scheduled; until it appears, the only reliable barrier is user caution about app sources. The other question the record leaves explicit is procedural: if vendors claim an "exclusive final right of vulnerability disclosure," who gets to set the clock between report, patch, and public notice? That remains a matter of policy and practice — and, in this instance, the researcher chose to publish after months of limited response.




