CVE-2017-8850 affects OnePlus One, X, 2, 3, and 3T devices, allowing attackers to install different operating systems (HydrogenOS over OxygenOS and vice versa) due to lenient updater-scripts and shared OTA verification keys. This medium-severity vulnerability (CVSS 5.9) can be exploited by Man-in-the-Middle attackers during the unencrypted update process or by physical attackers using adb sideload. The potential impact involves exploiting vulnerabilities patched in one OS but not the other, and expanding the attack surface. There is no evidence of active exploitation, nor are there known public exploit codes like Metasploit or ExploitDB, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.