[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f4RMsFgAt28twCK5KlgIFls7Lpghkbq_9a-hGiBuLxbY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"ee71ef2a-6069-4b07-8aa5-beb3b4399800","unpatched-oxygenos-flaws-enable-root-access-without-user-permissions","b5ae1d6b-b07a-4953-a6ac-ea0c15cf7f5d","Unpatched OxygenOS Flaws Enable Root Access Without User Permissions","Two unpatched vulnerabilities in OnePlus's OxygenOS allow locally installed malicious apps to silently escalate privileges to root level, bypassing Android's permission model entirely. This is critical because root access exposes the entire device — including credentials, communications, and sensitive data — without any user interaction or awareness. The situation is compounded by OnePlus's failure to promptly patch confirmed flaws and its aggressive stance toward the researcher who responsibly disclosed them. Vendor attempts to suppress or control vulnerability disclosure undermine the security community's ability to protect end users, and delays in patching leave millions of devices at risk. This case highlights that device manufacturers must treat privilege escalation vulnerabilities as critical-priority patches.","**Immediate actions:**\n- Avoid installing untrusted or sideloaded apps on affected OnePlus\u002FOPPO devices until patches are released.\n- Monitor official OnePlus\u002FOPPO security bulletins and apply firmware updates immediately upon release.\n- Consider restricting affected devices from accessing sensitive corporate resources until the vulnerabilities are remediated.\n\n**Long-term improvements:**\n- Establish a formal mobile device management (MDM) policy that enforces OS patch compliance across all managed endpoints.\n- Maintain a complete inventory of mobile device models and OS versions to rapidly assess exposure when new vulnerabilities are disclosed.\n- Evaluate vendor security responsiveness and patch cadence as part of device procurement and supply chain risk assessments.\n\n**Detection measures:**\n- Deploy mobile threat defense (MTD) solutions capable of detecting anomalous privilege escalation behavior on Android devices.\n- Enable audit logging for device management events and alert on unexpected root or elevated-privilege activity.\n- Monitor threat intelligence feeds for proof-of-concept exploit releases tied to unpatched mobile OS vulnerabilities.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Controlled Use of Administrative Privileges","CIS Control 2: Inventory and Control of Software Assets","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST AC-6: Least Privilege","NIST SI-2: Flaw Remediation","NIST RA-5: Vulnerability Monitoring and Scanning","ISO\u002FIEC 27001: A.12.6.1 Management of Technical Vulnerabilities","OWASP Mobile Top 10: M1 - Improper Platform Usage","GDPR Article 32: Security of Processing (for organizations handling personal data on affected devices)","published","2026-09-24T20:20:43.829555+00:00","2026-09-24T20:20:43.247+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Funpatched-oneplus-flaws-let-installed.html","unpatched-oneplus-flaws-let-installed-android-apps-gain-root-without-permissions-7a9b3e","Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]