A researcher discovered that a plain installable APK with no special permissions can chain two separate vulnerabilities—one via an audio debug service and another via a vendor HAL—to achieve root access (uid 0 with full Linux capabilities) on OnePlus 15 devices running OxygenOS 16. OnePlus confirmed the bug affects at least 151 devices across multiple brands (including OPPO), with fixes rolled out in version 16.0.10.500(EX01); 18 devices remain unpatched.
Background
Android's SELinux sandbox restricts normal apps to the untrusted_app domain, but vendor HAL bugs and debug interfaces can bypass this isolation. This is a recurring class of high-severity issues in the Android ecosystem, especially on devices with custom vendor partitions.
- Source
- Lobsters
- Published
- Sep 30, 2026 at 01:25 AM
- Score
- 9.0 / 10