Story perspectives
OnePlus OxygenOS Vulnerability Exposes SMS, MFA Risks
9/26/2025
37 9
1 of 1
Story summary
- The CVE-2025-10184 vulnerability in OnePlus OxygenOS lets apps access SMS/MMS without consent, risking MFA.
- Discovered by Rapid7, the flaw affects OxygenOS 12–15 and OnePlus 8T/10 Pro; likely all affected devices.
- OnePlus will roll out a patch starting mid-October 2025.
- Users should switch to authenticator apps and limit installations to trusted sources; the risk reflects OEM modifications to Android core components.
