Researcher Disclosed OnePlus Security Flaws

A security researcher revealed two vulnerabilities in OxygenOS after receiving legal threats from OnePlus.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of a metal processor chip with circuit paths and a single padlock, representing mobile software security vulnerabilities.
Security researcher Rasmus Moorats disclosed two unpatched vulnerabilities in OnePlus OxygenOS that allow unauthorized applications to gain root administrative access. AI Illustration. Upload story photo >

Live Poll

Should smartphone manufacturers have the exclusive right to control the disclosure of software security flaws?

Security researcher Rasmus Moorats has publicly disclosed two unpatched vulnerabilities in OnePlus OxygenOS software. The flaws allow installed applications to gain root access to affected devices without user permission.

Why it matters

The vulnerabilities pose a significant security risk by enabling unauthorized root access, potentially compromising device integrity. The situation has sparked industry debate over the legal risks researchers face when disclosing software flaws without manufacturer consent.

The exploit chains a vulnerability in the AtlasService with a flaw in the olc2 hardware helper to execute arbitrary shell commands. These two flaws allow unauthorized root access across devices running OxygenOS 16.

The players

Rasmus Moorats

Rasmus Moorats is the security researcher who identified and publicly disclosed the vulnerabilities in OnePlus software.

OnePlus

OnePlus is a mobile device manufacturer that produces smartphones running the proprietary OxygenOS software.

OPPO

OPPO is a technology company that shares common software foundations with OnePlus devices.

The details

The AtlasService flaw permits any installed app to trigger system commands, while the olc2 service executes shell instructions without requiring secondary authentication. These combined weaknesses allow an application to bypass system security and gain administrative control.

Timeline

  1. April 18, 2026: Researcher reported the flaws to OnePlus.

  2. May 20, 2026: OnePlus confirmed the existence of the flaws and warned of legal liability.

  3. June 22, 2026: OnePlus provided a fix update.

  4. September 24, 2026: Researcher published the findings.

The Tech Race

The conflict reflects a growing tension in the cybersecurity industry between responsible disclosure practices and manufacturer-enforced non-disclosure policies. This situation highlights how companies often attempt to exert control over external research via the threat of litigation.

Users of affected OnePlus and OPPO devices should ensure their phones are updated to the latest software version to mitigate potential exploits. Unpatched vulnerabilities may leave personal data susceptible to unauthorized access from malicious applications.

The takeaway

Security research remains a critical component of mobile safety despite the ongoing friction between investigators and manufacturers. Users are encouraged to prioritize official security updates to safeguard their personal devices against potential exploits.

Further reading

Learn more about evolving threats in Cybersecurity.

Live Poll

Should smartphone manufacturers have the exclusive right to control the disclosure of software security flaws?