OnePlus and OPPO Devices Exposed to Permissionless Rooting via Two Chained Flaws

Security researcher Rasmus Moorats discovered two vulnerabilities in OnePlus's own software that, when chained, allow a malicious app installed by the user to gain root access without requesting any special permissions. The researcher demonstrated the attack on a OnePlus 15 running the latest OxygenOS. OnePlus acknowledged that the flaws affect many of its devices as well as those from OPPO, but has not yet released a patch.
The vulnerability chain discovered by researcher Rasmus Moorats targets OnePlus's proprietary software layer rather than the underlying Android operating system. Because the flaws require no special permissions, any app installed from any source could exploit them silently. The demonstration on a OnePlus 15 running the latest OxygenOS suggests even fully updated devices remain exposed.
OnePlus has confirmed the issue extends to OPPO handsets, which share software foundations. No patch has been released, leaving users reliant on cautious app installation until a fix arrives. The discovery highlights how manufacturer-customized software can introduce security gaps even when the base platform is secure.
This vulnerability could affect a substantial user base, given the popularity of OnePlus and OPPO devices globally. A malicious app gaining root access without permission requests could allow data theft, surveillance, or device takeover. Users may face risks from seemingly benign apps, undermining trust in app store ecosystems. Until a patch arrives, consumers may need to limit app installations to trusted sources, though even that may not fully mitigate the threat. The incident could also prompt broader scrutiny of how device manufacturers handle security in their custom software layers.