← Back to events
ActiveTech

Getting root on OnePlus 15 from an untrusted app

Photo: Lobsters

What happened

Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.

Summary assembled by rule from the sources below

Why it's spreading

Sources