OnePlus -phone errors could let devices send unwanted text messages – so be careful who you ping


  • CVE-2025-10184 Lets attackers read and send SMS, including 2FA codes
  • Vulnerability affects Oxygenos -Versions 12 to 15, used across many OnePlus -Units
  • Rapid7 revealed errors after failed contact; OnePlus has not yet released a solution

A vulnerability in the software used in OnePlus smartphones could allow threat actors to send SMS messages on behalf of the victim, experts have warned.

Even worse, it allows them to read SMS content, including multi-factor approval codes, in cases where SMS is created as the secondary 2FA layer chosen, security researchers from RAPID7 reassessed.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top