Drooid Logo
Back to today’s briefing

Story perspectives

OnePlus OxygenOS Vulnerability Exposes SMS, MFA Risks

9/26/2025

37 9

1 of 1

Story summary
  • The CVE-2025-10184 vulnerability in OnePlus OxygenOS lets apps access SMS/MMS without consent, risking MFA.
  • Discovered by Rapid7, the flaw affects OxygenOS 12–15 and OnePlus 8T/10 Pro; likely all affected devices.
  • OnePlus will roll out a patch starting mid-October 2025.
  • Users should switch to authenticator apps and limit installations to trusted sources; the risk reflects OEM modifications to Android core components.