important · Mobile — OnePlus
An ordinary Android app can extract an active OnePlus Cloud session token from the preinstalled account provider.
Affects
The preinstalled OnePlus Account application on OnePlus 13R Android phones, which brokers authentication to OnePlus Cloud services.
The provider’s custom permission lacks signature-level protection, and September retesting confirmed that the returned token was accepted by the regional API.
Detail and 2 sources
The flaw remains unresolved, but end-to-end profile modification was not reproduced on current US or EMEA test accounts.
Chain to watch
Retest token-authorized API calls with a supported regional account.→↓Map the read and write operations authorized by the extracted token on current firmware.→↓The token’s full authorized API scope on current firmware remains unknown.
Unverified chainRepeat signed and encrypted OnePlus Cloud API requests with a supported regional account.