A no-permission OxygenOS app can chain two vendor services into full root execution.
The same APK worked on stock OnePlus 15 and OnePlus 12 Pro devices; OnePlus says additional OnePlus and OPPO products are affected.
Affects
OnePlus OxygenOS, the vendor Android distribution on OnePlus phones; OnePlus says related OPPO products are also affected.
What it enables
Root command execution from an ordinary Android application
Attacker gets a plain no-permission APK running in the Android untrusted_app domain.→↓The APK calls AtlasService.setEvent with the audio-dumpsys event and attacker-controlled property value.→↓audioDumpInfo runs as UID 0 in the dumpstate domain and interpolates that value into system(), producing a restricted root shell.→↓The root dumpstate process calls the olc2 HAL doShell method, whose only caller check is UID 0.→↓The HAL executes the supplied command in vendor_qti_init_shell with all Linux capabilities.
Why this matters
The chain starts in Android’s ordinary untrusted_app domain with no requested permissions and ends in a vendor shell with all Linux capabilities.
Detail and 2 sources
Required access
Execution as a normal installed Android app with no requested permissions
Affected versions
OnePlus 15 CPH2747 running OxygenOS 16.0.3.503, security patch level 2026-02-01, OnePlus 12 Pro CPH2581, software version not stated
Proof of concept
Demonstrated by the researcher
An unrestricted AtlasService Binder call places attacker-controlled text into audioDumpInfo, which interpolates it into system() while running as UID 0. That first step provides a restricted root process in the dumpstate domain.
The process can then call olc2 doShell, whose only caller check is UID 0, and execute commands in vendor_qti_init_shell with all capabilities. OnePlus announced remediation, but it did not publish a complete affected-product list.
Evidence
The researcher ran the same no-permission APK successfully on stock OnePlus 15 and OnePlus 12 Pro devices.The published analysis traces both Binder calls, the command injection and the resulting UID and capability context.OnePlus confirmed broader OnePlus and OPPO exposure but did not publish the complete affected list.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.