Unpatched flaw in OnePlus phones lets rogue apps text messages
ID: 71af264a-5275-5b90-8723-6855e3806cd2
STIX ID: report--71af264a-5275-5b90-8723-6855e3806cd2
Feed Name: Bleeping Computer
Threat Score
A flaw in OnePlus' OxygenOS (CVE-2025-10184) stems from extra exported Telephony content providers missing required permissions, allowing any installed app to access and infer SMS contents via blind SQL injection; Rapid7 published a PoC and tested multiple OnePlus models across OxygenOS 12–15. OnePlus initially did not respond but later reported a global fix rollout scheduled for mid-October; mitigations include minimizing installed apps and avoiding SMS-based 2FA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
