Security Flaw in OnePlus Smartphones Permits Applications to Retrieve Text Messages; Update Release Approaching

Security Flaw in OnePlus Smartphones Permits Applications to Retrieve Text Messages; Update Release Approaching

Security Flaw in OnePlus Smartphones Permits Applications to Retrieve Text Messages; Update Release Approaching

The vulnerability allows applications to access your SMS/MMS without consent, jeopardizing two-factor authentication codes.

(Image credit: Apoorva Bhardwaj / Android Central)

Disclaimer

Like our content? Be sure to designate Android Central as a favored source in Google Search, and discover why doing so will keep you informed on the most recent news, reviews, features, and additional information.

Essential information

  • Devices operating on OxygenOS 12 to 15 contain a significant flaw (CVE-2025-10184) that permits dubious apps to read and transmit your messages without authorization.
  • Malicious actors could capture your 2FA codes or send messages on your behalf, facilitating account hijacking.
  • OnePlus has announced that a global update will be issued in mid-October to close the SMS vulnerability.

For those with a OnePlus device operating on OxygenOS 12 through <a data-analytics-id="inline-link" href="https://www.androidcentral.com/apps-software/i-used-oxygenos-15-for-a-week-these-are-my-favorite-features" data-before-rewrite