By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: If you have a OnePlus phone, your text messages might be at risk
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > If you have a OnePlus phone, your text messages might be at risk
News

If you have a OnePlus phone, your text messages might be at risk

News Room
Last updated: 2025/09/29 at 1:10 PM
News Room Published 29 September 2025
Share
SHARE

Summary

  • Security company Rapid7 has uncovered a major vulnerability within OnePlus phones that could leave users’ SMS and MMS texting data exposed to bad actors.
  • This security risk appears to impact all newer OnePlus phones running OxygenOS 12 and later, though Rapid7 has only tested OnePlus 8T and 10 Pro 5G models.
  • OnePlus has since acknowledged the vulnerability, and has confirmed plans to roll out a software patch in the coming weeks.

Cybersecurity company Rapid7 has identified a major new permission bypass vulnerability within modern OnePlus smartphones called CVE-2025-10184. This novel exploit, if leveraged by bad actors, could enable rogue applications to read sensitive SMS and MMS text message data from the system’s Telephony provider service — all without the explicitly granted permission of the user.

Theoretically, CVE-2025-10184 might impact all OnePlus devices running OxygenOS 12, 14, and 15, though Rapid7 itself only tested OnePlus 8T and 10 Pro 5G models. Older OnePlus handsets running Oxygen 11 (based on Android 11) or previous appear to be unaffected by the exploit.

“The issue stems from the fact that sensitive internal content providers are accessible without permission, and are vulnerable to SQL injection. Based on our analysis, this vulnerability could be leveraged to bypass the core Android READ_SMS permission to silently exfiltrate users’ SMS data without their consent and break SMS-based MFA systems,” writes Rapid7 in a blog post.

Without getting into too much technical detail, it appears that the exploit stems from modifications made by OnePlus to the Android Open Source Project’s (AOSP’s) core Telephony package back in the Android 12 days, in order to integrate extra content providers into the service. While the company implemented the appropriate read permissions into its modification, there was some kind of oversight made in the addition of effective write permissions.

An official fix is on the way

OnePlus acknowledges the vulnerability and is working on a patch

In a statement provided to 9to5Google, OnePlus has confirmed that it’s aware of this newly-surfaced texting vulnerability found within OxygenOS, and that it has successfully implemented a working fix for it. The company goes on to say that the patch will be pushed out across the globe via an over-the-air (OTA) software update “starting from mid-October.”

It’s great to hear that OnePlus is working to plug this potentially major security vulnerability across its portfolio of handsets. That being said, reports of the company failing to respond to Rapid7’s initial private inquiry are concerning, as are Rapid7’s characterizations of the OnePlus Bug Bounty Program’s “restrictive Non Disclosure Agreement” terms and conditions.

In any case, a fix is on the way, which means OnePlus users can breathe a sigh of relief. In the meantime, Rapid7 recommends cutting down on non-essential apps, avoiding the installation of apps from unknown sources, and making use of a dedicated authenticator app for two-factor authentication (2FA) as opposed to relying on SMS one-time password (OTP) codes.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Apple News+ just added The Washington Post at no extra cost – 9to5Mac
Next Article Linux 6.18 Power Management Brings Panther Lake Power Slider & New Drivers
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Intel Releases New LLM Scaler Betas For GenAI On Battlemage GPUs
Computing
Crash Bandicoot N-Sane Trilogy (Nintendo Switch) Review
Gadget
Can’t-Miss Early Prime Big Deal Days Bargains on Gaming Laptops and Desktops
News
The Next Era of Global Trade: Tech, Transparency, and Trust according to Vincent Iacopella
Gadget

You Might also Like

News

Can’t-Miss Early Prime Big Deal Days Bargains on Gaming Laptops and Desktops

7 Min Read

One Tech Tip: OpenAI adds parental controls to ChatGPT for teen safety

4 Min Read
News

Are H-1B Changes ‘A Strategic Opening’ For Startup Creation Or An ‘Insurmountable Founder Tax’?

10 Min Read
News

Anthropic launches Claude Sonnet 4.5 — ‘best coding model in the world’

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?