Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » Vulnerabilities & Exploits » These OnePlus smartphones may be leaking your SMS messages to hackers

These OnePlus smartphones may be leaking your SMS messages to hackers

These OnePlus smartphones may be leaking your SMS messages to hackers

https://etimg.etb2bimg.com/thumb/msid-124176116,imgsize-24140,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/these-oneplus-smartphones-may-be-leaking-your-sms-messages-to-hackers.jpg


OnePlus smartphones running OxygenOS versions 12 through 15 contain a critical security vulnerability that allows malicious apps to read and send SMS messages without user permission, cybersecurity firm Rapid7 revealed this week. The flaw, tracked as CVE-2025-10184 with a severity score of 8.2 out of 10, potentially affects millions of devices manufactured over the past four years.

The vulnerability enables attackers to access sensitive text messages, including two-factor authentication codes, and send unauthorized SMS messages on behalf of victims. Only devices still running 2020’s OxygenOS 11 or earlier remain unaffected by this security breach.

OnePlus acknowledges problem

Rapid7 researchers discovered the flaw in May 2024 but struggled to contact OnePlus through traditional channels. After failed attempts at private disclosure, the security firm published its findings publicly on Monday. OnePlus didn’t acknowledge the issue until earlier this week, when the company finally confirmed awareness of the exploit, according to 9to5Google.

The vulnerability stems from modifications OnePlus made to Android’s standard Telephony package when transitioning to OxygenOS 12. The company added three content providers to the service but failed to properly secure write permissions, creating an exploitable weakness that allows any installed app to access SMS data without user consent.

OnePlus in a statement to 9to5Google: “We acknowledge the recent disclosure of CVE-2025-10184 and have implemented a fix. This will be rolled out globally via software update starting from mid-October. OnePlus remains committed to protecting customer data and will continue to prioritize security improvements.

What should affected OnePlus smartphone users do

OnePlus has promised a global software update starting mid-October to address the security flaw. However, until the patch arrives, cybersecurity experts strongly advise users to take immediate protective action.

Rapid7 recommends OnePlus owners install only essential apps from trusted sources and remove unnecessary applications. Users should immediately switch from SMS-based two-factor authentication to authenticator apps and migrate conversations from text messaging to encrypted platforms like WhatsApp or Telegram.

The discovery highlights ongoing security challenges facing Android device manufacturers who customize Google’s operating system, particularly when modifications affect core system components responsible for handling sensitive user data.

  • Published On Sep 27, 2025 at 09:16 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Providers Company in India

 

 

 

 

 

 

 

 

 

 

 

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket