
OnePlus AtlasService and olc2 Chain Grants Permissionless Root on Stock OxygenOS 16
OnePlus and OPPO share the vulnerable code paths; no CVE or public advisory exists. The attack requires only a malicious app with zero permissions, matching a separate August 2026 technique that affected Samsung, Xiaomi, and Realme devices. Users remain dependent on app-store trust until patches appear.
Moorats reported both flaws on 18 April 2026. OnePlus confirmed them on 20 May, asserted exclusive control over disclosure timing, and threatened legal action if technical details were published without consent. The company cited European cybersecurity rules as justification while scheduling an internal fix that had not shipped by 24 September. The first flaw lets any installed app invoke a root-owned service that pipes attacker-controlled text into a system command inside the dumpstate zone. The second flaw, reachable only after the first succeeds, executes arbitrary shell commands inside a higher-privilege context, enabling kernel module loading.
OnePlus: No CVE or public advisory published within 45 days of 24 September 2026 disclosure
Sources (3)
- [1]Moorats Disclosure Timeline(https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html)
- [2]Calif August 2026 OEM Root Report(https://calif.security/2026/08/android-oem-root)
- [3]Rapid7 2025 OnePlus Disclosure Record(https://www.rapid7.com/blog/post/2025/03/oneplus-delayed-response/)