E-Ink News Daily

← Back to list

Getting root on OnePlus 15 from an untrusted app

A researcher discovered that a plain installable APK with no special permissions can chain two separate vulnerabilities—one via an audio debug service and another via a vendor HAL—to achieve root access (uid 0 with full Linux capabilities) on OnePlus 15 devices running OxygenOS 16. OnePlus confirmed the bug affects at least 151 devices across multiple brands (including OPPO), with fixes rolled out in version 16.0.10.500(EX01); 18 devices remain unpatched.

Background

Android's SELinux sandbox restricts normal apps to the untrusted_app domain, but vendor HAL bugs and debug interfaces can bypass this isolation. This is a recurring class of high-severity issues in the Android ecosystem, especially on devices with custom vendor partitions.

Source
Lobsters
Published
Sep 30, 2026 at 01:25 AM
Score
9.0 / 10