OPPO Mobile Telecommunication Corp., Ltd. develops a widely deployed mobile platform centered on its ColorOS operating system and FIND and RENO series handsets. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur across firmware and device software through weakness classes including out-of-bounds writes, command injection, privilege-escalation flaws, and path-traversal issues that are characteristic of mobile operating systems and system-level components. Defenders should prioritize security updates for OPPO devices in their inventory; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by OPPO Mobile Telecommunication Corp., Ltd. over time
Of all the CVEs published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA, 68.0% affect products that OPPO Mobile Telecommunication Corp., Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by OPPO Mobile Telecommunication Corp., Ltd., 94.4% are self-published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA.
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22070CRITICAL ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. | Apr 30, 2026 | 9.8 | 35 | NO | NO |
CVE-2021-23247CRITICAL A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engin | Apr 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-26310CRITICAL There is a command injection problem in the old version of the mobile phone backup app. | Aug 9, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-11830CRITICAL QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0. | Nov 19, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-11829CRITICAL Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722. | Nov 19, 2020 | 9.8 | 28 | NO | NO |
CVE-2023-26311CRITICAL A remote code execution vulnerability in the webview component of OPPO Store app.
| Aug 10, 2023 | 9.8 | 25 | NO | NO |
CVE-2021-23246HIGH In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user information disclosure. | Mar 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-23243HIGH In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be used. | Sep 27, 2021 | 7.8 | 25 | NO | NO |
CVE-2021-23244HIGH ColorOS pregrant dangerous permissions to apps which are listed in a whitelist xml named default-grant-permissions.But some apps in whitelist is not installed, attacker can disguis | Dec 27, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-11831CRITICAL OvoiceManager has system permission to write vulnerability reports for arbitrary files, affected product is com.oppo.ovoicemanager V2.0.1. | Nov 19, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by OPPO Mobile Telecommunication Corp., Ltd..
Media articles that mention a CVE ID that affects a product developed by OPPO Mobile Telecommunication Corp., Ltd. — matched by CVE ID, not by vendor name.