CVE-2025-10184 is an information disclosure vulnerability in OnePlus OxygenOS affecting the system-provided Telephony provider. According to the provided content, any application installed on the device can read SMS/MMS message content and related metadata from the Telephony provider without the required permission, user interaction, consent, or user notification. The root cause is described as a combination of missing permission enforcement for write operations in several content providers—com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, and com.android.providers.telephony.ServiceNumberProvider—and a blind SQL injection flaw in the update method of those providers. Together, these issues allow a malicious local application to abuse provider operations to access protected SMS/MMS data that should normally be restricted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a comprehensive exploit and mitigation toolkit for CVE-2025-10184, a critical SQL injection vulnerability in the Telephony ContentProvider on OPPO, OnePlus, and realme Android devices (ColorOS and derivatives). The exploit is implemented as an Android app and Xposed module. The main exploit (app/src/main/java/yuu/xposed/MainActivity.java) demonstrates a blind SQL injection technique to extract SMS data from the device without permissions or user interaction, leveraging the vulnerable ContentProvider. The exploit works by inserting a dummy row, parsing user-supplied SELECT queries, and using a binary search approach to reconstruct SMS data character by character. The repository also includes a defensive Xposed module (app/src/main/java/yuu/xposed/jump/TelephonyHookModule.kt) that hooks the update methods of the vulnerable providers, blocks unauthorized access, notifies the user, and logs attempts to a file. The code is primarily in Java and Kotlin, and the repository includes build scripts and configuration for Android/Xposed development. The README provides detailed background, affected versions, mitigation strategies, and user guidance. No network endpoints are used; all exploitation is local to the device. The exploit is operational and can be used both for demonstration and for defensive purposes.
This repository is a Proof-of-Concept (PoC) Android APK for CVE-2025-10184, a permission bypass vulnerability in OPPO/OnePlus telephony content providers (com.*.providers.telephony). The vulnerability allows any installed app to read SMS messages without the READ_SMS permission by exploiting a SQL injection flaw in the content providers. The main exploit logic is implemented in 'app/src/main/java/poc/chutchut/cpblindsqli/MainActivity.java', which constructs and executes SQL queries against the vulnerable content providers (notably 'content://service-number/service_number', 'content://push-mms/push', and 'content://push-shop/push_shop'). The APK provides a UI for entering SQL queries and dumping SMS data, demonstrating the impact of the vulnerability. The repository includes build scripts, AndroidManifest, and supporting files for building and testing the APK. The exploit is operational as a PoC and does not include weaponized or automated payloads beyond the demonstration of unauthorized SMS access. The README provides background, affected versions, and remediation advice.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.