Researcher Disclosed Unpatched OnePlus Security Flaws

A security researcher revealed two critical vulnerabilities in OxygenOS, leading to a legal dispute with the manufacturer.

Updated on Sept. 24, 2026 in Cybersecurity

Isometric editorial illustration of a stylized silicon wafer stack with a glowing central aperture, representing mobile system security architecture.
Researcher Rasmus Moorats disclosed two unpatched security vulnerabilities in OnePlus's OxygenOS, prompting a legal dispute over the manufacturer's disclosure policies. AI Illustration. Upload story photo >

Live Poll

Should smartphone manufacturers have the exclusive right to control the disclosure of software security flaws?

Researcher Rasmus Moorats has publicly disclosed two unpatched security vulnerabilities in OxygenOS that permit apps to gain root access without user permission. OnePlus confirmed these findings in May 2026 but threatened the researcher with legal action for unauthorized disclosure.

Why it matters

This disclosure highlights the tension between independent security research and corporate control over software vulnerability reporting. The presence of these flaws on devices like the OnePlus 15 underscores the risks of inadequate permission checks in mobile system services.

The vulnerability relies on chaining two flaws to bypass security: the AtlasService improperly accepts calls without permission checks, while the olc2 hardware helper executes arbitrary shell instructions. This allows an app to escalate privileges to root access.

The players

Rasmus Moorats

A security researcher who identified and publicly disclosed the vulnerabilities in the OxygenOS mobile operating system.

OnePlus

A smartphone manufacturer producing hardware that utilizes the OxygenOS software stack.

OPPO

A mobile device manufacturer that shares the affected software components with OnePlus.

The details

The first flaw resides in AtlasService, a system component that fails to validate the origin of incoming requests. By exploiting this, an app can interface with debugging tools to gain restricted access, which then triggers the second flaw in the olc2 hardware helper. The olc2 service then executes shell instructions—system-level commands—without secondary authentication, granting the app full root control over the device. The researcher projects this vulnerability affects all devices running OxygenOS 16.

Timeline

  1. April 18, 2026: Researcher reported the flaws to OnePlus.

  2. May 20, 2026: OnePlus confirmed the flaws and warned of legal liability.

  3. June 22, 2026: OnePlus provided a fix update.

  4. September 24, 2026: Researcher published the findings.

The Tech Race

The threat of legal action against security researchers by manufacturers follows a historical pattern often debated under the interpretation of the Computer Fraud and Abuse Act. This specific case reflects the ongoing tension in applying unauthorized access laws to collaborative versus adversarial security disclosures.

Users of the OnePlus 15 and OnePlus 12 Pro may remain at risk if they have not applied the fix update provided by the company in June 2026. Owners should verify their software version in device settings to ensure they are running the latest security patch.

The takeaway

The conflict between manufacturer disclosure policies and independent researchers continues to shape how critical mobile software flaws are remediated. Watch for further updates on whether OnePlus expands its patch availability to older devices beyond the current scope of the report.

Further reading

For more information on the evolving state of mobile device safety, visit our Cybersecurity section.

Live Poll

Should smartphone manufacturers have the exclusive right to control the disclosure of software security flaws?

Researcher Disclosed Unpatched OnePlus Security Flaws