Skip to finding
important · Mobile — OnePlus

An ordinary Android app can extract an active OnePlus Cloud session token from the preinstalled account provider.

Affects

The preinstalled OnePlus Account application on OnePlus 13R Android phones, which brokers authentication to OnePlus Cloud services.

The provider’s custom permission lacks signature-level protection, and September retesting confirmed that the returned token was accepted by the regional API.

Detail and 2 sources

The flaw remains unresolved, but end-to-end profile modification was not reproduced on current US or EMEA test accounts.

Chain to watch
Retest token-authorized API calls with a supported regional account.→↓Map the read and write operations authorized by the extracted token on current firmware.→↓The token’s full authorized API scope on current firmware remains unknown.
Unverified chainRepeat signed and encrypted OnePlus Cloud API requests with a supported regional account.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 11, 2026