A high-severity flaw in the preinstalled com.oneplus.account app on OnePlus 13R devices allows any installed malicious app to obtain an authenticated OnePlus Cloud session token. The exported OPAccountProvider content provider relies on com.oneplus.account.READ_ACCOUNT_INFO, a permission that third-party apps can declare because it is not restricted to software signed by OnePlus; an app can then invoke get_account_oneplus_token to retrieve oldSecondaryToken without user interaction beyond installation.
The exposed token was accepted by the OnePlus Cloud API and was demonstrated to enable modification of victim account data, creating a path to account session takeover. Doyensec confirmed the token exposure remained in firmware CPH2691_16.0.10.500(EX01) and disclosed the issue publicly after OnePlus had not remediated it.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Doyensec publicly disclosed the unresolved OnePlus 13R OEM-app vulnerability, describing how a malicious installed app could obtain an authenticated OnePlus Cloud token without user interaction and impersonate the victim in cloud services.
Doyensec confirmed that an untrusted app could still extract a OnePlus account token from OPAccountProvider and that the token remained accepted by the OnePlus Cloud API. The researchers could not reproduce the prior account-data modification on the latest firmware because of regional-mechanism changes, but the underlying token exposure persisted.
A $720 bug bounty was paid for the reported OnePlus account-token exposure vulnerability.
OnePlus validated Doyensec's finding and assigned it a high-severity rating, after it had initially been reported as critical.
Doyensec disclosed the vulnerability to OnePlus, reporting that an untrusted installed application could access the exported OPAccountProvider and retrieve an authenticated OnePlus Cloud session token.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourceblog.doyensec.com
Open sourcefrida.re
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.