8.2
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Description
The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks.
The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.
The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.
Basic Information
ID
CVE-2025-10184
Source
rapid7
Published
Sep 23, 2025 at 13:02
Affected Product
Vendor
OnePlus
Product
OxygenOS
Version
11.*
Affected Versions
OnePlus OxygenOS 12.*
OnePlus OxygenOS 13.*
OnePlus OxygenOS 14.*
OnePlus OxygenOS 15.*
OnePlus OxygenOS 13.*
OnePlus OxygenOS 14.*
OnePlus OxygenOS 15.*