Close Menu

    Subscribe to Updates

    Get the latest tech news from Tallwire.

      What's Hot

      Artemis II Splashdown Signals A Step Closer to Mass Space Travel

      April 12, 2026

      Anthropic Code Leak Raises Questions About AI Security and Industry Oversight

      April 8, 2026

      NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

      April 8, 2026
      Facebook X (Twitter) Instagram
      • Tech
      • AI
      • Get In Touch
      Facebook X (Twitter) LinkedIn
      TallwireTallwire
      • Tech

        NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

        April 8, 2026

        OpenAI Expands Influence With Strategic TBPN Media Acquisition

        April 8, 2026

        Cybersecurity Veteran Turns Focus To Drone Hacking After Decades Battling Malware

        April 6, 2026

        Anonymous Social App Surges In Saudi Arabia, Testing Limits Of Digital Freedom

        April 6, 2026

        Peter Thiel’s Bold Ag-Tech Gamble Signals High-Tech Disruption of Traditional Ranching

        April 6, 2026
      • AI

        Anthropic Code Leak Raises Questions About AI Security and Industry Oversight

        April 8, 2026

        The Rise Of Agentic AI Signals A Shift From Tools To Autonomous Digital Actors

        April 8, 2026

        AI Chatbots Draw Scrutiny As Teens Engage In Intimate Roleplay And Emotional Dependency

        April 8, 2026

        Ai-Powered Startup Signals Rise Of One-Person Billion-Dollar Companies

        April 8, 2026

        OpenAI Secures Historic $122 Billion Funding Round at $852 Billion Valuation

        April 7, 2026
      • Security

        Anthropic Code Leak Raises Questions About AI Security and Industry Oversight

        April 8, 2026

        DeFi Platform Drift Halts Operations After Multi-Million Dollar Crypto Hack

        April 7, 2026

        Fake WhatsApp App Exposes Users To Government Spyware Operation

        April 7, 2026

        ICE Deploys Controversial Spyware Tool In Drug Trafficking Investigations

        April 7, 2026

        Telehealth Firm Discloses Breach Amid Rising Digital Health Vulnerabilities

        April 6, 2026
      • Health

        European Crackdown Targets Social Media’s Impact on Children

        April 8, 2026

        AI Chatbots Draw Scrutiny As Teens Engage In Intimate Roleplay And Emotional Dependency

        April 8, 2026

        Australia Moves To Curb Social Media Addiction Among Youth With Expanded Under-16 Ban

        April 5, 2026

        Australia’s eSafety Regulator Warns Big Tech As Teens Circumvent Social Media Restrictions

        April 5, 2026

        Meta Finally Held Accountable For Harming Teens, But Real Reform Remains Uncertain

        April 2, 2026
      • Science

        Artemis II Splashdown Signals A Step Closer to Mass Space Travel

        April 12, 2026

        Peter Thiel’s Bold Ag-Tech Gamble Signals High-Tech Disruption of Traditional Ranching

        April 6, 2026

        White House Tech Advisor David Sacks Steps Down To Lead Presidential Science Advisory

        March 31, 2026

        Blue Origin’s Orbital Data Center Push Signals New Frontier in Tech Infrastructure

        March 27, 2026

        Quantum Cryptography Pioneers Awarded Computing’s Highest Honor

        March 25, 2026
      • Tech

        Peter Thiel’s Bold Ag-Tech Gamble Signals High-Tech Disruption of Traditional Ranching

        April 6, 2026

        Zuckerberg Quietly Offers Musk Support As Tech Titans Align Around Government Power

        April 4, 2026

        White House Tech Advisor David Sacks Steps Down To Lead Presidential Science Advisory

        March 31, 2026

        Another Billionaire Signals Exit As California’s Taxes Drives Out High-Profile Entrepreneurs

        March 28, 2026

        Bezos Eyes $100 Billion War Chest To Rewire Legacy Industry With AI

        March 28, 2026
      TallwireTallwire
      Home»Tech»OnePlus Faces SMS Exploit, Patch Promised for October
      Tech

      OnePlus Faces SMS Exploit, Patch Promised for October

      Updated:December 25, 20253 Mins Read
      Facebook Twitter Pinterest LinkedIn Tumblr Email
      OnePlus Faces SMS Exploit, Patch Promised for October
      OnePlus Faces SMS Exploit, Patch Promised for October
      Share
      Facebook Twitter LinkedIn Pinterest Email

      OnePlus smartphones running OxygenOS 12 through 15 are vulnerable to a serious permission-bypass exploit (CVE-2025-10184), allowing any installed app to silently read SMS, MMS, and associated metadata without user consent or explicit permission; the flaw was publicly disclosed by security researchers at Rapid7 after repeated failed attempts to coordinate with OnePlus, and the company has since committed to rolling out a fix globally starting mid-October.

      Sources: 9t05 Google, Rapid7

      Key Takeaways

      – The vulnerability stems from OnePlus’s modifications to the Android Telephony content providers (e.g. PushMessageProvider, PushShopProvider, ServiceNumberProvider) which lacked write permissions and were vulnerable to blind SQL injection, enabling apps to bypass READ_SMS restrictions.

      – The flaw enables attackers to exfiltrate SMS content — including one-time codes used for SMS-based multi-factor authentication — thereby weakening a key security defense.

      – Until the patch arrives, users should minimize installed apps to only trusted sources, transition from SMS-based 2FA to authenticator apps, and avoid using SMS for high-sensitivity communication.

      In-Depth

      In a move that’s raising serious security alarms in the mobile world, researchers at Rapid7 have unveiled a permission-bypass vulnerability in OnePlus devices that could quietly expose your text messages to malicious apps. The flaw, labeled CVE-2025-10184, is believed to affect devices running OxygenOS versions 12 through 15, and was introduced when OnePlus altered core Android Telephony components. Under normal operations, Android enforces strict permissions around SMS and MMS access — apps must explicitly request READ_SMS or related permissions and users must grant consent. But OnePlus’s changes introduced new content providers (PushMessageProvider, PushShopProvider, ServiceNumberProvider) without proper write restrictions, leaving them open to abuse. By chaining blind SQL injection techniques, a malicious app can infer or outright exfiltrate SMS content without triggering any user prompts or alerts.

      Rapid7 says that SMS-based multi-factor authentication (MFA) protections are especially vulnerable here, since attackers could intercept OTPs or codes meant for account verification. The seriousness is underlined by the fact that attackers need no special permissions or user interaction for the exploit to succeed. In their disclosure, Rapid7 noted repeated failed attempts to engage with OnePlus before making the issue public. Only after the disclosure did OnePlus respond, promising a global patch rollout by mid-October.

      In practice, users of vulnerable OnePlus phones are left in limbo. There’s no way to confirm whether your data has been accessed in the interim, so caution is the only viable recourse. Security-minded users should immediately remove nonessential or untrusted apps, rely on app stores with stronger vetting, and — most importantly — switch from SMS-based 2FA to more secure methods like time-based one-time passwords (TOTP) or hardware keys. Also, sensitive communications should bypass SMS entirely, favoring end-to-end encrypted messaging platforms. As the patch approaches, OnePlus users should watch carefully for software updates and apply them quickly when they arrive.

      Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
      Previous ArticleOneleet Secures $33M to Challenge “Compliance Theater” in Cybersecurity
      Next Article Ontra’s Sharp AI Move Tightens the Noose on Legal Backlog in Private Markets

      Related Posts

      NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

      April 8, 2026

      OpenAI Expands Influence With Strategic TBPN Media Acquisition

      April 8, 2026

      Cybersecurity Veteran Turns Focus To Drone Hacking After Decades Battling Malware

      April 6, 2026

      Anonymous Social App Surges In Saudi Arabia, Testing Limits Of Digital Freedom

      April 6, 2026
      Add A Comment
      Leave A Reply Cancel Reply

      Editors Picks

      NASA Astronauts Use iPhones to Capture Historic Artemis II Mission Images

      April 8, 2026

      OpenAI Expands Influence With Strategic TBPN Media Acquisition

      April 8, 2026

      Cybersecurity Veteran Turns Focus To Drone Hacking After Decades Battling Malware

      April 6, 2026

      Anonymous Social App Surges In Saudi Arabia, Testing Limits Of Digital Freedom

      April 6, 2026
      Popular Topics
      Series A Viral Ransomware spotlight Satya Nadella Samsung Series B SpaceX Tesla Cybertruck Tim Cook Software trending Sam Altman Taiwan Tech Tesla UAE Tech Startup Quantum computing Robotics Sundar Pichai
      Major Tech Companies
      • Apple News
      • Google News
      • Meta News
      • Microsoft News
      • Amazon News
      • Samsung News
      • Nvidia News
      • OpenAI News
      • Tesla News
      • AMD News
      • Anthropic News
      • Elbit News
      AI & Emerging Tech
      • AI Regulation News
      • AI Safety News
      • AI Adoption
      • Quantum Computing News
      • Robotics News
      Key People
      • Sam Altman News
      • Jensen Huang News
      • Elon Musk News
      • Mark Zuckerberg News
      • Sundar Pichai News
      • Tim Cook News
      • Satya Nadella News
      • Mustafa Suleyman News
      Global Tech & Policy
      • Israel Tech News
      • India Tech News
      • Taiwan Tech News
      • UAE Tech News
      Startups & Emerging Tech
      • Series A News
      • Series B News
      • Startup News
      Tallwire
      Facebook X (Twitter) LinkedIn Threads Instagram RSS
      • Tech
      • Entertainment
      • Business
      • Government
      • Academia
      • Transportation
      • Legal
      • Press Kit
      © 2026 Tallwire. Optimized by ARMOUR Digital Marketing Agency.

      Type above and press Enter to search. Press Esc to cancel.