Oneplus

Oxygenos

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 23.09.2025 13:15:27
  • Zuletzt bearbeitet 24.09.2025 18:11:24

The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being acce...

  • EPSS 0.14%
  • Veröffentlicht 29.03.2018 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:28:43

An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in tur...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 11.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increase...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 11.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check that the current version is lower than or equal to the...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 11.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verification keys, attackers can install HydrogenOS over OxygenOS and vice versa,...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 11.05.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fact that both products share the same 'ro.build.produc...

  • EPSS 0.08%
  • Veröffentlicht 25.04.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboo...

  • EPSS 0.06%
  • Veröffentlicht 26.03.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 19.03.2017 20:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android wher...

Exploit
  • EPSS 1.84%
  • Veröffentlicht 12.03.2017 05:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by issuing the 'fastboot oem disable_dm_verity' command. Having dm-verity di...