Discover top-rated products across every category — all handpicked for quality and value you can count on

When you’ve got a OnePlus cellphone, your textual content messages is perhaps in danger

Abstract

  • Safety firm Rapid7 has uncovered a significant vulnerability inside OnePlus telephones that might depart customers’ SMS and MMS texting knowledge uncovered to unhealthy actors.
  • This safety threat seems to influence all newer OnePlus telephones operating OxygenOS 12 and later, although Rapid7 has solely examined OnePlus 8T and 10 Professional 5G fashions.
  • OnePlus has since acknowledged the vulnerability, and has confirmed plans to roll out a software program patch within the coming weeks.

Cybersecurity firm Rapid7 has recognized a significant new permission bypass vulnerability inside modern OnePlus smartphones known as CVE-2025-10184. This novel exploit, if leveraged by unhealthy actors, might allow rogue functions to learn delicate SMS and MMS textual content message knowledge from the system’s Telephony supplier service — all with out the explicitly granted permission of the consumer.

Theoretically, CVE-2025-10184 would possibly influence all OnePlus gadgets operating OxygenOS 12, 14, and 15, although Rapid7 itself solely examined OnePlus 8T and 10 Pro 5G fashions. Older OnePlus handsets operating Oxygen 11 (primarily based on Android 11) or earlier seem like unaffected by the exploit.

“The difficulty stems from the truth that delicate inside content material suppliers are accessible with out permission, and are susceptible to SQL injection. Primarily based on our evaluation, this vulnerability might be leveraged to bypass the core Android READ_SMS permission to silently exfiltrate customers’ SMS knowledge with out their consent and break SMS-based MFA methods,” writes Rapid7 in a blog post.

With out moving into an excessive amount of technical element, it seems that the exploit stems from modifications made by OnePlus to the Android Open Source Project’s (AOSP’s) core Telephony package deal again within the Android 12 days, with the intention to combine further content material suppliers into the service. Whereas the corporate applied the suitable learn permissions into its modification, there was some sort of oversight made within the addition of efficient write permissions.

An official repair is on the way in which

OnePlus acknowledges the vulnerability and is engaged on a patch

In an announcement provided to 9to5Google, OnePlus has confirmed that it is conscious of this newly-surfaced texting vulnerability discovered inside OxygenOS, and that it has efficiently applied a working repair for it. The corporate goes on to say that the patch can be pushed out throughout the globe by way of an over-the-air (OTA) software program replace “ranging from mid-October.”

It is nice to listen to that OnePlus is working to plug this probably main safety vulnerability throughout its portfolio of handsets. That being mentioned, stories of the corporate failing to answer Rapid7’s preliminary personal inquiry are regarding, as are Rapid7’s characterizations of the OnePlus Bug Bounty Program’s “restrictive Non Disclosure Settlement” phrases and situations.

In any case, a repair is on the way in which, which suggests OnePlus customers can breathe a sigh of aid. Within the meantime, Rapid7 recommends chopping down on non-essential apps, avoiding the set up of apps from unknown sources, and making use of a devoted authenticator app for two-factor authentication (2FA) versus counting on SMS one-time password (OTP) codes.

Trending Merchandise

- 32% HP 17.3″ FHD Essential Busine...
Original price was: $952.37.Current price is: $643.49.

HP 17.3″ FHD Essential Busine...

0
Add to compare
- 7% HP 24mh FHD Computer Monitor with 2...
Original price was: $159.99.Current price is: $148.00.

HP 24mh FHD Computer Monitor with 2...

0
Add to compare
- 17% ASUS 15.6” Vivobook Go Slim La...
Original price was: $229.99.Current price is: $189.99.

ASUS 15.6” Vivobook Go Slim La...

0
Add to compare
- 19% Lenovo V14 Gen 3 Enterprise Laptop ...
Original price was: $739.00.Current price is: $599.00.

Lenovo V14 Gen 3 Enterprise Laptop ...

0
Add to compare
- 28% Logitech MK270 Wi-fi Keyboard And M...
Original price was: $38.54.Current price is: $27.93.

Logitech MK270 Wi-fi Keyboard And M...

0
Add to compare
- 41% Sevenhero H602 ATX PC Case with 5 A...
Original price was: $185.88.Current price is: $109.99.

Sevenhero H602 ATX PC Case with 5 A...

0
Add to compare
- 24% Wireless Keyboard and Mouse Ultra S...
Original price was: $41.77.Current price is: $31.77.

Wireless Keyboard and Mouse Ultra S...

0
Add to compare
- 39% Zalman i3 NEO ATX Mid Tower Gaming ...
Original price was: $105.27.Current price is: $63.80.

Zalman i3 NEO ATX Mid Tower Gaming ...

0
Add to compare
- 35% Motorola MG7550 – Modem with ...
Original price was: $183.52.Current price is: $119.95.

Motorola MG7550 – Modem with ...

0
Add to compare
- 12% Lenovo 15.6″ FHD Laptop, Inte...
Original price was: $429.00.Current price is: $378.99.

Lenovo 15.6″ FHD Laptop, Inte...

0
Add to compare
.

We will be happy to hear your thoughts

Leave a reply

ShopBestGoods
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart