Quick Answer
OnePlus says 151 maintained export models across OnePlus, OPPO, and realme have received fixes for two OxygenOS flaws that let a normal installed APK gain root access without special permissions. Eighteen models still awaited October OTA releases as of September 28, 2026. Update your phone, confirm its build number, and avoid installing untrusted APKs while your model remains pending.
Key Takeaways
- OnePlus said 151 maintained export models had received fixes by September 28, 2026.
- The exploit chain started from an ordinary Android APK with no special permissions.
- The two flaws involved OxygenOS AtlasService and the Oplus Log Core vendor HAL.
- Fixed builds begin at specific version numbers across OxygenOS 15 and OxygenOS 16 branches.
- Eighteen OnePlus, OPPO, and realme models were still scheduled for October OTA releases.
What is the OnePlus root vulnerability?
The OnePlus root vulnerability is a chain of two OxygenOS flaws that allowed a standard Android APK to gain uid 0, also called root access, without requesting special Android permissions. Researcher Rasmus Moorats published a proof of concept on September 24, 2026, showing that the attack could reach root-level execution with all Linux capabilities. Moorats’ technical disclosure describes the affected OxygenOS components and the remediation timeline.
Root access matters because Android normally separates apps from protected operating-system functions. An app that reaches uid 0 can operate outside the restrictions that normally limit ordinary applications. The disclosure did not require the user to grant the malicious APK a special permission, which makes the vulnerability more serious than an issue that depends on access to the camera, microphone, location, or files.
The first issue was in OxygenOS AtlasService, a component that runs as root. AtlasService accepted Binder calls from any process without checking whether the caller had permission. Binder is Android’s system for communication between processes, so a missing caller check can let an untrusted app ask a privileged component to perform work that should be restricted.
The second issue involved the Oplus Log Core, or “olc2,” vendor hardware abstraction layer and its doShell method. Moorats found that chaining the AtlasService issue with the olc2 issue produced root-level execution. The practical risk is limited to a phone that installs a malicious APK, but the absence of special permission prompts means users should treat unfamiliar APK files as unsafe while waiting for an update.
Which OnePlus, OPPO, and realme devices received patches?
OnePlus told Moorats that 151 maintained export models had received fixes by September 28, 2026. The covered group included maintained OnePlus, OPPO, and realme export devices, although OnePlus did not publicly list every individual model or every affected software version in the information provided to the researcher.
The absence of a complete public model list creates an important limitation for owners. A phone can belong to one of the three brands and still need a different update schedule, region-specific build, or carrier approval. The most sensible response is to check the software version installed on the phone rather than assuming that a device is protected because a related model received an update.
OnePlus also said 18 models were still pending over-the-air releases scheduled for October. An OTA release is a software update delivered through the phone’s update system. Pending status does not establish that every unpatched device is exposed in the same way, because OnePlus did not publicly identify the complete affected model and version set.
Security updates can arrive on different timelines across brands and regions. That rollout constraint is common in Android software delivery, but it matters more for a root flaw because the vulnerability begins with an installed application. Users who are already cautious about malicious wallet extensions should apply the same standard to Android packages: do not install APKs from unfamiliar messages, file-sharing links, or unofficial download pages.
What software versions fix the OnePlus root vulnerability?
The OnePlus root vulnerability is fixed beginning with three stated build thresholds: 16.0.10.500 on the 16.1.0 line, 16.0.5.1200 on the 16.0.0 line, and 15.0.0.2000 on the 15.0.0 line. OnePlus provided those version thresholds to Moorats as part of its September 28 remediation update.
| OxygenOS software line | Fixed builds begin at | What owners should do |
|---|---|---|
| 16.1.0 | 16.0.10.500 | Check whether the installed build meets or exceeds the stated fixed build. |
| 16.0.0 | 16.0.5.1200 | Install the available OTA update before sideloading any apps. |
| 15.0.0 | 15.0.0.2000 | Confirm the phone has received the current security build for its model. |
The version numbers are useful because they give owners a concrete way to evaluate the update installed on their phone. A device that reports a lower build on the relevant software line has not reached the stated fixed threshold. At the same time, users should not try to manually flash unfamiliar firmware packages to get ahead of the OTA schedule, because a wrong package or interrupted installation can create a separate device problem.
The OnePlus 15 received build CPH2745_16.0.10.500(EX01) on August 18, 2026, and Moorats’ timeline says that build fixed the bugs on that model. Owners of other phones should not assume that the OnePlus 15 build applies to their device. Device-specific firmware identifiers and regional variants can differ.
How did the researcher demonstrate root access on a OnePlus 15?
The proof of concept worked on a OnePlus 15 after Moorats installed the same unmodified APK that he had developed on a rooted OnePlus 12 Pro. Moorats said the APK worked on the OnePlus 15 on the first attempt. The result showed that the issue was not limited to a specially modified test environment once the APK ran on the daily-driver phone.
The proof of concept began as an ordinary Android app package. The APK did not need special permissions because the AtlasService flaw accepted Binder calls without a caller permission check, and the second flaw in the Oplus Log Core vendor HAL completed the path to root-level execution. The attack chain therefore relied on privileged system components behaving incorrectly, not on the user accepting a visible high-risk permission prompt.
The demonstration does not mean that every APK is dangerous or that every OnePlus phone is compromised. The disclosed method still required a user to install an APK. That limitation is meaningful because Google Play and Android’s normal installation protections reduce exposure compared with downloading packages from untrusted websites or receiving them through messages.
Android users should keep app installation limited to sources they trust and should review unexpected download prompts carefully. Similar social-engineering tactics also appear in browser-based fraud, including fake technical support alerts that pressure users to take immediate action. The safe action is to close suspicious pages, avoid downloading unknown files, and install the official OTA update when it appears.
How do you check whether your OnePlus phone has the fix?
OnePlus phone owners should check the installed software build under Settings and install the available OTA update if the phone offers one. The exact menu wording can vary by model and OxygenOS release, but the update screen identifies the installed version and checks OnePlus’ update service for a newer build.
- Open Settings on the OnePlus phone.
- Open the phone’s About device or software update area.
- Check the installed OxygenOS version and build number.
- Compare the build with the applicable fixed threshold for the 16.1.0, 16.0.0, or 15.0.0 software line.
- Install the official OTA update if the phone reports one is available.
- Restart the phone after the update completes and confirm that the updated build is installed.
Back up important files before installing any major system update. An OTA security update is the recommended response, but any system change can be interrupted by low battery, insufficient storage, or an unexpected error. Charge the phone and keep adequate free storage before beginning the update.
Owners should stop and contact OnePlus support if the update fails repeatedly, the phone cannot restart normally after installation, or the device shows a software build that does not match the offered update. Do not unlock the bootloader, flash unofficial firmware, or use root tools to address this vulnerability. Those actions can make the phone less secure and do not replace the vendor fix.
What should owners do while an OTA update is still pending?
OnePlus owners with a pending OTA update should avoid installing APKs from untrusted sources until the phone reaches the fixed software build. The disclosed exploit used a normal installed APK and did not need special permissions, so waiting for a permission prompt is not a sufficient defense against this specific attack path.
Use apps from established sources and do not install software sent through unsolicited messages, unfamiliar cloud-storage links, or websites that claim an urgent update is required. The threat model here is an app that reaches the device, not a vulnerability that activates merely because a user owns an affected phone. That distinction means careful installation habits reduce risk while the vendor completes the rollout.
Users should also remove APK files they downloaded but do not recognize, particularly if the files came from a message or an unfamiliar web page. Removing a downloaded installer does not confirm whether an app was already installed, so review the phone’s installed-app list if there is any concern. A recent AI agent data exposure also illustrates why users should limit what they install and share when a service or application has not earned their trust.
OnePlus owners should not rely on antivirus claims, root-detection apps, or unofficial patch packages as proof that the device is safe. The verified mitigation is the relevant OnePlus software build. Until that update arrives, the practical action is to reduce APK exposure and watch the official system update screen.
Why does this OnePlus vulnerability matter for Android security?
The OnePlus root vulnerability matters because it crossed Android’s app sandbox through two privileged OxygenOS components. Android’s security model is designed to prevent a normal app from acting as the operating system, and a chain that reaches uid 0 bypasses that intended separation. The disclosed proof of concept therefore demonstrates a serious design and permission-checking failure in the affected software path.
The remediation progress is also important. OnePlus said 151 maintained export devices across its OnePlus, OPPO, and realme brands had fixes, while 18 models remained scheduled for October OTA releases. That is a substantial patch response, but the pending devices and incomplete public model list mean users still need to verify their individual build number.
Mobile security depends on both vendor updates and user choices. A patch closes the reported flaw, while avoiding untrusted APKs reduces the chance that an attacker can use an installation-based exploit before the patch reaches the phone. Owners should apply updates promptly, but they should not make unsupported claims about whether a particular model is vulnerable when OnePlus has not published its complete affected-device list.
The OnePlus disclosure is separate from other platform-specific security incidents, including Apple’s CoreGraphics zero-day patch. The common practical lesson is that security updates matter most when they address a confirmed route to elevated access or data exposure. Users should enable automatic updates where available and check manually when a serious vendor disclosure affects their device family.
FAQ
Is the OnePlus root vulnerability fixed?
Yes, OnePlus said 151 maintained OnePlus, OPPO, and realme export models had received fixes by September 28, 2026. Eighteen models were still awaiting OTA releases scheduled for October, so owners should check their installed build number.
Did the OnePlus exploit require Android permissions?
No, the proof-of-concept APK did not require special Android permissions. The exploit chain worked because OxygenOS AtlasService accepted Binder calls without a caller permission check.
Which OxygenOS versions contain the fix?
The stated fixed builds begin at 16.0.10.500 on the 16.1.0 line, 16.0.5.1200 on the 16.0.0 line, and 15.0.0.2000 on the 15.0.0 line. Owners should compare their phone’s installed build with the applicable threshold.
Can a malicious APK gain root access on a OnePlus phone?
Yes, Moorats’ proof of concept showed that a normal installed APK could chain the two disclosed OxygenOS flaws into root-level execution. The attack required the APK to be installed, so avoiding untrusted downloads reduces exposure before an update arrives.
Should OnePlus owners manually flash a firmware update?
No, OnePlus owners should install the official OTA update offered for their specific model and region. Stop and contact OnePlus support if the OTA update fails, because flashing an incorrect firmware package can create additional system problems.
