A critical, unpatched vulnerability in proprietary software used across OnePlus, OPPO, and Realme smartphones reportedly allows a malicious application to silently gain root access—without requesting any user permissions—posing a significant risk for enterprise security and device integrity.

According to a report by The Hacker News, security researcher Rasmus Moorats detailed an exploit chain that leverages two flaws within OnePlus's OxygenOS and the underlying Oplus software framework. The attack is notably stealthy: a user need only install an application, which then reportedly uses the chained flaws to escalate privileges to root, bypassing Android's standard permission requests and security warnings.

The report states that OnePlus confirmed to Moorats that the vulnerabilities affect a broad range of its devices, as well as products from sister brands OPPO and Realme, all owned by parent company BBK Electronics. If accurate, this indicates a systemic issue within shared, OEM-specific software components that form a critical but often overlooked layer of the Android security stack.

For enterprises managing large groups of devices from these manufacturers, the flaw represents an urgent concern. An attacker could exploit it to circumvent Mobile Device Management (MDM) policies, extract sensitive data, or maintain persistent access to a corporate network. The risk is amplified by the reported lack of an official patch from the vendors.

The discovery underscores that device security extends beyond the core Android Open Source Project (AOSP) to the custom software layers installed by hardware vendors. These components can introduce significant and widespread vulnerabilities if not rigorously secured.

Enterprise Risk and Immediate Recommendations
  • Core Risk: Applications can reportedly attain full device control (root) silently, evading all user-facing security prompts and potentially undermining MDM controls.
  • Affected Systems: Confirmed on OnePlus devices running OxygenOS; the shared Oplus framework reportedly links the flaw to OPPO and Realme devices as well.
  • Vendor Status: No patch or mitigation timeline has been provided by OnePlus or its sister brands as of this report.
  • Mitigation Steps for IT Administrators:
    1. Inventory Affected Devices: Immediately catalog all managed OnePlus, OPPO, and Realme devices across the organisation.
    2. Restrict App Sources: Enforce strict policies against installing applications from untrusted sources, including third-party app stores and direct APK files. Heighten scrutiny for all app installations.
    3. Monitor for Anomalies: Utilize endpoint detection and MDM tools to watch for unusual system behavior that may indicate a root compromise, such as unauthorized process changes or disabled security settings.
    4. Engage Vendors and Plan: Contact device manufacturers and MDM providers for security updates. Incorporate this systemic OEM vulnerability into risk assessments for future device procurement and security policy updates.

據報,OnePlus、OPPO 及 Realme 智能手機所採用的專有軟件中存在一項嚴重且未獲修補的安全漏洞,該漏洞允許惡意應用程式在無需請求任何用戶權限的情況下靜默獲取最高權限(root),對企業安全及設備完整性構成重大風險。

根據 The Hacker News 的報導,安全研究人員 Rasmus Moorats 詳細闡述了一條漏洞利用鏈,該鏈條利用了 OnePlus OxygenOS 及底層 Oplus 軟件框架內的兩個缺陷。此攻擊具有顯著的隱蔽性:用戶僅需安裝一個應用程式,該應用程式據稱便會利用這些串連的缺陷將權限提升至最高權限,繞過 Android 標準的權限請求及安全警告。

報導指出,OnePlus 向 Moorats 確認,受影響的漏洞廣泛波及其裝置,以及母公司步步高電子旗下姊妹品牌 OPPO 和 Realme 的產品。若情況屬實,這表明共享的 OEM 專屬軟件組件中存在系統性問題,這些組件是 Android 安全架構中關鍵但常被忽視的一層。

對於管理這些製造商龐大裝置組合的企業而言,該漏洞構成迫切關注。攻擊者可利用此漏洞繞過移動設備管理(MDM)策略、提取敏感數據,或對企業網絡維持持久存取權限。由於製造商目前據報尚未提供官方補丁,風險因而加劇。

此發現凸顯裝置安全範圍不僅限於核心 Android 開源項目(AOSP),更延伸至硬件製造商安裝的自訂軟件層。若未經嚴格安全保障,這些組件可能引入重大且廣泛的安全漏洞。

企業風險與即時建議
  • 核心風險: 應用程式據報可靜默獲取設備完整控制權(最高權限),規避所有面向用戶的安全提示,並可能削弱 MDM 控制。
  • 受影響系統: 已確認於運行 OxygenOS 的 OnePlus 裝置上發現;共享的 Oplus 框架據報亦將此漏洞關聯至 OPPO 及 Realme 裝置。
  • 製造商狀態: 截至本報告發佈時,OnePlus 及其姊妹品牌均未提供補丁或緩解時間表。
  • IT 管理員緩解措施:
    1. 盤點受影響設備: 立即清點機構內所有受管理的 OnePlus、OPPO 及 Realme 裝置。
    2. 限制應用來源: 強制實施嚴格政策,禁止安裝來自不受信任來源的應用程式,包括第三方應用商店及直接 APK 文件。對所有應用安裝提高審查標準。
    3. 監控異常行為: 利用端點檢測及 MDM 工具監控可能指示最高權限入侵的異常系統行為,例如未經授權的進程變更或已停用的安全設置。
    4. 聯繫製造商並制定計劃: 聯繫設備製造商及 MDM 供應商以獲取安全更新。將此系統性 OEM 漏洞納入未來設備採購及安全策略更新的風險評估中。

新聞來源 / Original News Source