OnePlus vulnerabilities concentrate across its OxygenOS mobile operating system and associated flagship devices such as the OnePlus 3T, 3, 2, and One, with the disclosed issues skewing strongly toward critical-severity outcomes. The recurring weakness classes—cleartext transmission of sensitive information, improper privilege and access control, and improper authentication—reflect the authentication, encryption, and permission-enforcement demands of a mobile platform. Live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oneplus over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5554HIGH An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authenticatio | Jan 23, 2017 | 8.1 | 27 | NO | NO |
CVE-2017-11105CRITICAL The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that | Aug 3, 2017 | 9.8 | 26 | NO | NO |
CVE-2017-5626CRITICAL OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding | Mar 12, 2017 | 9.8 | 26 | NO | NO |
CVE-2023-26309CRITICAL A remote code execution vulnerability in the webview component of OnePlus Store app.
| Aug 10, 2023 | 9.8 | 25 | NO | NO |
CVE-2017-5624CRITICAL An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by iss | Mar 12, 2017 | 9.8 | 25 | NO | NO |
CVE-2016-10370HIGH An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of ar | May 11, 2017 | 7.5 | 22 | NO | NO |
CVE-2017-5622MEDIUM With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical | Mar 26, 2017 | 5.9 | 22 | NO | NO |
CVE-2017-8851MEDIUM An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification | May 11, 2017 | 5.9 | 21 | NO | NO |
CVE-2017-8850MEDIUM An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verificatio | May 11, 2017 | 5.9 | 21 | NO | NO |
CVE-2020-7958MEDIUM An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA. The firmware was found to contain functionality that allows a privileged user (root) in the Rich Execution En | Apr 14, 2020 | 6.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oneplus.
Media articles that mention a CVE ID that affects a product developed by Oneplus — matched by CVE ID, not by vendor name.