All OnePlus Devices at Risk of Remote Attacks from Four Unpatched Vulnerabilities

Critical Vulnerabilities Discovered in OnePlus Devices: Immediate Caution Advised

Recent cybersecurity research has uncovered significant vulnerabilities affecting all OnePlus smartphones, including models such as One, X, 2, 3, and 3T. A report by Roee Hay at Aleph Security reveals four critical weaknesses in the devices running OxygenOS 4.1.3 and earlier, as well as HydrogenOS 3.0 and below. These issues pose a serious security risk to users worldwide, particularly as OnePlus has not yet issued patches after being notified of these vulnerabilities in January.

One particular vulnerability enables a Man-in-the-Middle (MitM) attack, allowing a remote attacker to downgrade a device’s operating system. This downgrade opens up exposure to previously patched vulnerabilities, making it easier for malicious actors to exploit the device further. The concern escalates with two additional flaws that permit attackers to replace any version of OxygenOS with HydrogenOS or vice versa, potentially installing malicious ROMs filled with spyware.

The ramifications of these vulnerabilities are profound. Notably, the insecure transmission of Over-the-Air (OTA) updates via HTTP without TLS was identified as a critical failure in OnePlus’s security design. Despite being signed with a digital signature, these updates are susceptible to interception, which can compromise the integrity of the device’s operating system.

Another serious flaw allows attackers to downgrade the OS of targeted devices to earlier, more vulnerable versions. This issue exemplifies poor security practices, as all OnePlus OTA updates share the same digital signing key. Therefore, devices will accept any OTA image regardless of bootloader status, which largely goes against standard Android functionality designed to prevent such downgrades.

In a troubling twist, the vulnerabilities enable attackers to manipulate the system by replacing any version of OxygenOS on a device with HydrogenOS, or vice versa. As both operating systems utilize the same OTA verification keys, this weakness further increases the potential for exploitation. Additionally, a specific vulnerability exists within OnePlus X and One, where an attacker can swap out software designed for one model with that of another, risking the device’s operability until a factory reset is performed.

The researcher has made available proof-of-concept code on GitHub, illustrating the severity of these flaws. Consequently, OnePlus users are urged to be vigilant, particularly when connecting to untrusted Wi-Fi networks, as exploitation requires both the attacker and the targeted device to share the same network environment.

The vulnerabilities highlighted embody several MITRE ATT&CK tactics, such as initial access and privilege escalation. By leveraging unsecured OTA updates, an attacker can gain unauthorized access to a device and manipulate its operating system, increasing the vulnerability landscape significantly.

Given the critical nature of these findings, it is imperative for OnePlus to address these issues urgently to protect users from potential exploitation while emphasizing the necessity of secure communication protocols like HTTPS and TLS. Business owners and tech-savvy consumers should remain alert and consider best practices for securing their devices in light of these revelations.

Source link