Products: 12
    Vulnerabilities: 16
    Known Exploited: 0
    3
    Critical Level Threats
    3
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-10184

    OnePlus OxygenOS Telephony provider permission bypass

    Last Modified: Apr 15, 2026
    Published: Sep 23, 2025

    CVE-2023-26309

    A remote code execution vulnerability in the webview component

    Last Modified: Nov 21, 2024
    Published: Aug 10, 2023

    CVE-2020-13626

    OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.

    Last Modified: Nov 21, 2024
    Published: Oct 09, 2020

    CVE-2020-7958

    An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA. The firmware was found to contain functionality that allows a privileged user (root) in the Rich Execution Environment (REE) to obtain bitmap images from the fingerprint sensor because of Leftover Debug Code. The issue is that the Trusted Application (TA) supports an extended number of commands beyond what is needed to implement a fingerprint authentication system compatible with Android. An attacker who is in the position to send commands to the TA (for example, the root user) is able to send a sequence of these commands that will result in the TA sending a raw fingerprint image to the REE. This means that the Trusted Execution Environment (TEE) no longer protects identifiable fingerprint data from the REE.

    Last Modified: Nov 21, 2024
    Published: Apr 14, 2020

    CVE-2017-5947

    An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.

    Last Modified: Nov 21, 2024
    Published: Mar 29, 2018
    Items Per Page
    Oneplus Vulnerabilities & Security CVEs | CVE-DB