Back to News
Market Impact: 0.55

Unpatched flaw in OnePlus phones lets rogue apps text messages

RPDGOOGLDELL
Cybersecurity & Data PrivacyTechnology & InnovationCompany FundamentalsManagement & Governance
Unpatched flaw in OnePlus phones lets rogue apps text messages

Rapid7 researchers have disclosed a critical, unpatched vulnerability (CVE-2025-10184) in OnePlus's OxygenOS (versions 12-15) that enables any installed application to access SMS data and metadata without explicit user permission, leveraging blind SQL injection. This flaw, stemming from modifications to the Android Telephony package, presents significant privacy and security risks for users of OnePlus devices, a brand with official U.S. market presence. After initial non-responsiveness to disclosure attempts, OnePlus has acknowledged the issue and committed to rolling out a global software fix starting mid-October, highlighting potential reputational and security challenges for the Chinese OEM.

Analysis

A critical, unpatched vulnerability (CVE-2025-10184) discovered by Rapid7 (RPD) in OnePlus's OxygenOS versions 12 through 15 presents a significant operational and reputational risk for the electronics maker. The flaw permits any installed application to access sensitive SMS data without user permission via a blind SQL injection, a consequence of OnePlus's custom modifications to the Android Telephony package. The company's failure to respond to seven private disclosure attempts from May to August underscores a severe weakness in its security incident response framework and corporate governance. Only after public disclosure did OnePlus acknowledge the issue, committing to a software fix by mid-October. This delayed reaction, coupled with user commentary referencing a history of security lapses, suggests a potential systemic issue with the company's security posture, which could erode consumer trust, particularly in the U.S. market where the brand has an official presence. For Rapid7, the discovery and disclosure process positively highlights its technical capabilities and reinforces its credibility within the cybersecurity industry.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

strongly negative

Sentiment Score

-0.70

Ticker Sentiment

DELL0.00
GOOGL0.00
RPD0.80

Key Decisions for Investors

  • This event serves as a strong positive data point for Rapid7 (RPD), validating its vulnerability research capabilities and enhancing its brand authority, which could act as a tailwind for enterprise client acquisition.
  • The significant security failure and poor governance demonstrated by OnePlus may create a competitive opening for rival smartphone manufacturers that have a stronger track record on security and timely software updates.
  • Investors should treat this incident as a material case study on operational risk, increasing scrutiny of corporate governance and security response protocols as key diligence items when evaluating companies in the consumer technology sector.