A serious security vulnerability in OnePlus ' OxygenOS allows any installed app to read SMS and MMS messages , without asking for permission or notifying users.

The vulnerability, tracked as CVE-2025-10184 , affects many OnePlus devices running OxygenOS versions 12 to 15. SMS-based multi-factor authentication (MFA) systems are compromised and sensitive personal communications can be exposed
Cybersecurity firm Rapid7 identified this permission bypass vulnerability in several OnePlus smartphone models, including the OnePlus 8T, OnePlus 10 Pro 5G, and possibly other devices.
The vulnerability arises from internal content providers that are not properly secured within the Android Telephony (com.android.providers.telephony) and can be exploited via SQL injection techniques.
OnePlus OxygenOS Vulnerability
The vulnerability exploits content provider system , which manages structured data access between applications.
See also: Salesforce CLI Installer: Vulnerability allows malicious code execution
OnePlus introduced three additional exported content providers in its OxygenOS implementation that are not present in stock Android: PushMessageProvider, PushShopProvider , and ServiceNumberProvider. These providers contain inadequate permission checks and lack proper SQL injection protection.
The most critical flaw exists in the ServiceNumberProvider class, where the update method accepts arbitrary SQL code via the “where parameter” without sanitization.

Malicious applications can exploit this vulnerability to carry out blind SQL injection attacks, using Boolean inference techniques to extract SMS data, character by character, from the device's message database.
The exploitation process involves creating SQL queries with UNION SELECT statements and substr functions to systematically extract message contents.
Impact of vulnerability
This vulnerability has significant security implications beyond simply intercepting messages. It effectively bypasses Android's READ SMS permission system, allowing malicious apps to silently access SMS data without user consent or system notifications.
See also: CISA: Chrome zero-day vulnerability in KEV Catalog
More importantly, this situation also puts SMS-based MFA systems, which are used by banking apps, social media platforms, and other services, at risk.
The vulnerability affects OxygenOS versions 12, 14, and 15 across multiple device models. Notably, the OxygenOS 11 versions tested were not vulnerable, suggesting that the security flaw was introduced during the OxygenOS 12 development cycle in 2021.
Rapid7 believes that the issue could be exploited for surveillance activities by state hackers and authoritarian regimes seeking to monitor communications.
OnePlus reportedly ignored Rapid7's disclosure efforts in May 2025. Thus, the company was forced to disclose the vulnerability.

Users can mitigate exposure by removing non-essential apps, switching from SMS-based MFA to authenticator apps, and using messaging platforms with end-to-end encryption. These are some steps users can take until OnePlus releases security updates that address CVE-2025-10184.
See also: Chrome: Vulnerabilities allow data leakage & system crashes
OxygenOS: Security at risk
The disclosure of CVE-2025-10184 highlights a serious problem in the core of OxygenOS : weak protection of content providers that handle sensitive data. The issue is not just a privacy violation ; it undermines core security features of Android, as it removes the requirement for the READ_SMS permission . This means that any app – even one that seems harmless – can gain implicit access to messages and one-time passwords.
The lack of a timely response from OnePlus adds to the concern. When a vendor ignores responsible disclosures for months, devices are left exposed to zero-day attacks, especially in environments where surveillance or cyber espionage is common.
The case is a stark reminder that even popular custom ROMs can hide dangerous security flaws, requiring constant vigilance from consumers and IT professionals.
