Skip to finding
§
High
Mobile — Privilege
Confirmed

A no-permission OxygenOS app can chain two vendor services into full root execution.

The same APK worked on stock OnePlus 15 and OnePlus 12 Pro devices; OnePlus says additional OnePlus and OPPO products are affected.

Affects

OnePlus OxygenOS, the vendor Android distribution on OnePlus phones; OnePlus says related OPPO products are also affected.

What it enables

Root command execution from an ordinary Android application

Attacker gets a plain no-permission APK running in the Android untrusted_app domain.→↓The APK calls AtlasService.setEvent with the audio-dumpsys event and attacker-controlled property value.→↓audioDumpInfo runs as UID 0 in the dumpstate domain and interpolates that value into system(), producing a restricted root shell.→↓The root dumpstate process calls the olc2 HAL doShell method, whose only caller check is UID 0.→↓The HAL executes the supplied command in vendor_qti_init_shell with all Linux capabilities.
Why this matters

The chain starts in Android’s ordinary untrusted_app domain with no requested permissions and ends in a vendor shell with all Linux capabilities.

Detail and 2 sources
Required access

Execution as a normal installed Android app with no requested permissions

Affected versions

OnePlus 15 CPH2747 running OxygenOS 16.0.3.503, security patch level 2026-02-01, OnePlus 12 Pro CPH2581, software version not stated

Proof of concept

Demonstrated by the researcher

An unrestricted AtlasService Binder call places attacker-controlled text into audioDumpInfo, which interpolates it into system() while running as UID 0. That first step provides a restricted root process in the dumpstate domain.

The process can then call olc2 doShell, whose only caller check is UID 0, and execute commands in vendor_qti_init_shell with all capabilities. OnePlus announced remediation, but it did not publish a complete affected-product list.

Evidence
The researcher ran the same no-permission APK successfully on stock OnePlus 15 and OnePlus 12 Pro devices.The published analysis traces both Binder calls, the command injection and the resulting UID and capability context.OnePlus confirmed broader OnePlus and OPPO exposure but did not publish the complete affected list.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 25, 2026