{"id":1977,"date":"2026-09-25T10:41:01","date_gmt":"2026-09-25T05:11:01","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1977"},"modified":"2026-09-30T09:21:21","modified_gmt":"2026-09-30T03:51:21","slug":"oneplus-oxygenos-unpatched-root-flaws","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/","title":{"rendered":"OnePlus root vulnerability: What IT teams should know"},"content":{"rendered":"<p>Employees often use the same phone for everyday apps and access to company data. On September 24, 2026, a researcher disclosed the OnePlus root vulnerability, showing how an installed app could chain two OxygenOS flaws without special permissions.<\/p>\n<p>The finding gives IT teams a reason to review mobile device trust. An app\u2019s lack of permission requests does not establish that it is safe.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--info  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Who is affected by these OnePlus flaws?<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\tOnePlus device owners are the directly demonstrated affected group, including anyone using vulnerable phones for work. Testing included a stock OnePlus 15 running OxygenOS 16.0.3.503. Broader OnePlus and OPPO exposure was acknowledged during the disclosure process, but a complete model and software-version list was unavailable.<\/p>\n<p>This is a vulnerability disclosure, rather than an identified criminal campaign. Rasmus Moorats is the security researcher who demonstrated the issue, not a threat actor. Enterprises should therefore assess exposure through their device inventories instead of assuming a particular industry was targeted. Corporate phones and personally owned devices both deserve review when they access business applications, although their management options differ.    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h2>What happened?<\/h2>\n<h3>A local app crosses two privilege boundaries<\/h3>\n<p>The chain requires an app to be installed and running on the device. \u201cAndroid no-permission root\u201d describes the escalation: the app does not need special Android permissions to exploit these services. It does not mean the phone can be compromised remotely without that initial foothold.<\/p>\n<table>\n<thead>\n<tr>\n<th>Stage<\/th>\n<th>What the flaw enables<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>AtlasService accepts the call<\/td>\n<td>A root-running OEM service accepts requests without verifying the caller\u2019s authorization.<\/td>\n<\/tr>\n<tr>\n<td>An audio debugging tool processes the input<\/td>\n<td>Attacker-controlled text reaches a shell command, enabling root execution in the restricted <code>dumpstate<\/code> context.<\/td>\n<\/tr>\n<tr>\n<td>olc2 accepts the root caller<\/td>\n<td>A second OEM service executes shell commands after checking that the caller already has root privileges.<\/td>\n<\/tr>\n<tr>\n<td>Execution moves to a more privileged context<\/td>\n<td>The resulting process has broad Linux capabilities, including the capability associated with loading kernel modules.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Root privileges do not automatically remove every Android safeguard. SELinux, which restricts what processes can access, still constrains the final execution context. The demonstrated result should not be described as a proven defeat of every hardware or operating-system protection.<\/p>\n<h3>Disclosure and remaining uncertainties<\/h3>\n<p>Moorats reported the flaws on April 18, 2026. OnePlus confirmed them on May 20, and public disclosure followed on September 24.<\/p>\n<p>At disclosure, there was no publicly available fix, assigned CVE identifier, or vendor advisory naming the flaws. The affected-device list also remained incomplete. Organizations tracking OPPO security should check model-specific guidance rather than treating every OPPO phone as confirmed vulnerable.<\/p>\n<p>No known malicious campaign, credential theft, MFA bypass, or ransomware deployment accompanied the disclosure. The research demonstrated privilege escalation; persistent access across reboots and theft from enterprise applications were not established outcomes.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Why-Security-Teams-Need-Contextualized-Threat-Alerts.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Why Do Security Teams Need Contextualized Threat Alerts?<\/h4><p>Contextualized threat alerts help SOC teams reduce alert fatigue and prioritize threats faster.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/contextualized-threat-alerts\/\" aria-label=\"Why Do Security Teams Need Contextualized Threat Alerts?\"><\/a><\/div><\/div><\/div><\/p>\n<h2>Why this matters<\/h2>\n<p>Mobile endpoint security depends on the operating system enforcing boundaries between apps, users, and sensitive resources. Privileged OEM services become part of that trust boundary. If an ordinary app can abuse them, reviewing its requested permissions alone will miss the underlying risk.<\/p>\n<p>Android BYOD risk also extends beyond the work profile. Work profiles separate business apps and data, but they still depend on the underlying platform\u2019s security. A serious operating-system compromise warrants reassessing that separation; it does not prove that every work profile has been breached.<\/p>\n<p>For IT teams, the practical implication is to combine app controls, device monitoring, and access decisions. MFA remains valuable, but successful authentication does not establish that the device handling an authorized session is trustworthy.<\/p>\n<h2>How Hexnode can help<\/h2>\n<h3>Hexnode UEM: Reduce app exposure and review device trust<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> provides mobile device management controls that can support a measured response while organizations await vendor remediation.<\/p>\n<p><strong>Identify devices that need review.<\/strong> Device details and reports expose information such as manufacturer, model, OS version, ownership, and reported root status. Administrators can use that inventory to locate OnePlus and OPPO devices and prioritize users with sensitive access. Reported root status reflects the device&#8217;s root state at the time of check-in and is not a detection mechanism for this exploit, a device can be compromised via AtlasService\/olc2 without ever showing as rooted, so this field should not be relied on to identify affected devices.<\/p>\n<p><strong>Restrict unapproved installation paths.<\/strong> On supported Android Enterprise deployments, Hexnode can block app installation from unknown sources. This reduces one route for introducing a malicious app. However, it does not establish that every app from an approved store is safe.<\/p>\n<p><strong>Review application compliance.<\/strong> Hexnode displays compliance information for missing required apps and detected blocklisted apps. Beyond reporting, Hexnode can also take automated enforcement actions when a device is found non-compliant, for example, removing corporate Wi-Fi\/VPN profiles, wiping the Work Container, or restricting enterprise access.<\/p>\n<p><strong>Respect enrollment boundaries.<\/strong> Available restrictions depend on Android version, device support, and enrollment mode. On BYOD (Work Profile) enrollments, restricting &#8220;Unknown Sources&#8221; in Hexnode only locks down the corporate work container, personal-side sideloading on the device remains allowed. This restriction only extends to the full device on corporate-owned enrollments (COPE or Fully Managed). For personally owned phones, administrators should confirm each control&#8217;s scope rather than assume that a work-profile restriction governs personal apps.<\/p>\n<p>These measures improve oversight and reduce exposure. They do not patch AtlasService or olc2, and reported root status is not proof that this specific exploit will always be detected. Access restrictions also require an appropriately configured enforcement mechanism; a compliance report alone does not revoke application sessions.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android_thumbnail.webp?format=webp\" class=\"resource-box__image\" alt=\"Android_thumbnail\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android_thumbnail.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android_thumbnail-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android_thumbnail-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Android_thumbnail-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"Android_thumbnail\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Android Platform Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download the infographic to explore how Hexnode simplifies Android device management across every stage of the endpoint lifecycle.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/android-device-management\/'>\n                            Get the infographic\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>What security teams should do next<\/h2>\n<p>The OnePlus root vulnerability highlights a gap that permission reviews cannot address: an installed app may exploit privileged software already present on the phone. Organizations should act on that exposure without treating every potentially affected device as compromised.<\/p>\n<p>Start by identifying OnePlus and OPPO phones used for business access. Record their software versions, ownership, and business roles, then request model-specific remediation guidance. Review app installation policies and provide employees with a clear route for obtaining approved software.<\/p>\n<p>Where compromise is suspected, follow incident-response procedures and restrict sensitive access while investigating. Review associated sessions and credentials when evidence warrants it. Keep a vendor-confirmed fix as the remediation target, rather than assuming that enrollment or a clean status report resolves the flaws.<\/p>\n<p>Hexnode UEM can help maintain visibility and apply supported restrictions throughout this process. Assign an owner to track vendor updates, validate fixes, and confirm deployment across the relevant fleet.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f<\/h5><p>Sign up for Hexnode to manage Android devices, restrict app installations, and monitor compliance.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today\u202f\u202f<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Employees often use the same phone for everyday apps and access to company data. On&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1990,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[18],"class_list":["post-1977","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-mobile","product_category-unified-endpoint-management","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>OnePlus root vulnerability: Risks for Android fleets<\/title>\n<meta name=\"description\" content=\"Unpatched OnePlus flaws let installed Android apps gain root without permissions, raising BYOD and mobile fleet risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"OnePlus root vulnerability: Risks for Android fleets\" \/>\n<meta property=\"og:description\" content=\"Unpatched OnePlus flaws let installed Android apps gain root without permissions, raising BYOD and mobile fleet risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-25T05:11:01+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T03:51:21+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/OnePlus-root-vulnerability.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"OnePlus root vulnerability: What IT teams should know\",\"datePublished\":\"2026-09-25T05:11:01+00:00\",\"dateModified\":\"2026-09-30T03:51:21+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/\"},\"wordCount\":1071,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/OnePlus-root-vulnerability.png?format=webp\",\"articleSection\":[\"Mobile\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/\",\"name\":\"OnePlus root vulnerability: Risks for Android fleets\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/OnePlus-root-vulnerability.png?format=webp\",\"datePublished\":\"2026-09-25T05:11:01+00:00\",\"dateModified\":\"2026-09-30T03:51:21+00:00\",\"description\":\"Unpatched OnePlus flaws let installed Android apps gain root without permissions, raising BYOD and mobile fleet risk.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/OnePlus-root-vulnerability.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/OnePlus-root-vulnerability.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"OnePlus root vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/oneplus-oxygenos-unpatched-root-flaws\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"OnePlus root vulnerability: What IT teams should know\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"description\":\"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"OnePlus root vulnerability: Risks for Android fleets","description":"Unpatched OnePlus flaws let installed Android apps gain root without permissions, raising BYOD and mobile fleet risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/","og_locale":"en_US","og_type":"article","og_title":"OnePlus root vulnerability: Risks for Android fleets","og_description":"Unpatched OnePlus flaws let installed Android apps gain root without permissions, raising BYOD and mobile fleet risk.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-25T05:11:01+00:00","article_modified_time":"2026-09-30T03:51:21+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/OnePlus-root-vulnerability.png?format=webp","type":"image\/png"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"OnePlus root vulnerability: What IT teams should know","datePublished":"2026-09-25T05:11:01+00:00","dateModified":"2026-09-30T03:51:21+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/"},"wordCount":1071,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/OnePlus-root-vulnerability.png?format=webp","articleSection":["Mobile"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/","url":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/","name":"OnePlus root vulnerability: Risks for Android fleets","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/OnePlus-root-vulnerability.png?format=webp","datePublished":"2026-09-25T05:11:01+00:00","dateModified":"2026-09-30T03:51:21+00:00","description":"Unpatched OnePlus flaws let installed Android apps gain root without permissions, raising BYOD and mobile fleet risk.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/OnePlus-root-vulnerability.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/OnePlus-root-vulnerability.png?format=webp","width":1340,"height":700,"caption":"OnePlus root vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/oneplus-oxygenos-unpatched-root-flaws\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"OnePlus root vulnerability: What IT teams should know"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"description":"I\u2019m a technical content writer at Hexnode who loves simplifying tech. I break down complex ideas, remove the fluff, and help readers clearly understand our product for what it actually is: simple, reliable, and built to solve real problems.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1977","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1977"}],"version-history":[{"count":5,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1977\/revisions"}],"predecessor-version":[{"id":1983,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1977\/revisions\/1983"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1990"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1977"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1977"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}