A researcher disclosed a two-stage local privilege-escalation chain affecting OnePlus and OPPO devices running OxygenOS, including the OnePlus 15 on OxygenOS 16.0.3.503 and the OnePlus 12 Pro. A normally installable sideloaded app with no declared permissions can invoke the root-running AtlasService and inject shell commands through the audiodumpinfo debug service, obtaining execution as root in the SELinux dumpstate domain.
The chain then abuses the Oplus Log Core (olc2) vendor HAL's UID-0-restricted doShell method to run commands in the vendor_qti_init_shell SELinux domain, whose bounding set includes all Linux capabilities. OnePlus reportedly confirmed in May that multiple products and software versions are affected, but no complete affected-device list, CVE identifier, remediation details, or evidence of exploitation in the wild had been published.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A researcher published a two-stage local privilege-escalation chain allowing an unpermissioned Android app to obtain uid-0 execution through OxygenOS AtlasService and then execute commands through the Oplus Log Core vendor HAL. The chain was confirmed on a OnePlus 12 Pro and a OnePlus 15; no complete affected-device list or remediation details had been provided by OnePlus at publication.
OnePlus reportedly confirmed that the vulnerabilities affected multiple products and threatened legal action if the research was published.
OnePlus requested further details about the reported vulnerabilities, and the researcher supplied the requested information the same day.
The researcher reported the AtlasService command-injection issue and the Oplus Log Core HAL doShell authorization flaw to OnePlus security contacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
blog.nns.ee
Open sourcereddit.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.