CVE 8.2 HIGH

OnePlus OxygenOS Telephony provider permission bypass_CVE-2025-10184

8.2 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Description

The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks.

The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.

Basic Information

ID CVE-2025-10184
Source rapid7
Published Sep 23, 2025 at 13:02

Affected Product

Vendor OnePlus
Product OxygenOS
Version 11.*
Affected Versions OnePlus OxygenOS 12.*
OnePlus OxygenOS 13.*
OnePlus OxygenOS 14.*
OnePlus OxygenOS 15.*

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.