A critical vulnerability (CVE-2025-10184) in OnePlus OxygenOS allows any app to silently access SMS and MMS data without user interaction or special permissions. The flaw, present since OxygenOS 12, could enable attackers to bypass SMS-based MFA and access sensitive communications. Despite repeated attempts by Rapid7 to coordinate a fix, OnePlus has not responded, prompting public disclosure and recommendations for users to switch to authenticator apps and encrypted messaging.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The Register and BleepingComputer reported that OnePlus phones remained vulnerable to the unpatched flaw and that researchers had not received a fix from the vendor. The coverage emphasized the risk that rogue apps could read text messages on affected devices.
On its blog, Rapid7 disclosed CVE-2025-10184 and stated that the OnePlus OxygenOS telephony provider permission-bypass issue had not been fixed. The disclosure said the bug could expose users' text messages to rogue apps.
Rapid7 identified a vulnerability in OnePlus OxygenOS's telephony provider that could let a malicious app access text messages through a permission bypass. The flaw was later assigned CVE-2025-10184.
4 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcerapid7.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.