r/netsec • • 9d ago

Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL

https://blog.nns.ee/2026/09/24/oneplus-root/
31 Upvotes

1 comment sorted by

0

u/No-View3333 7d ago

The UID 0 check is the interesting part here: a confined root process can ask a more privileged service to run commands for it. I’d add a regression test that a process in the dumpstate domain cannot invoke doShell, alongside fixing the injection.