HT TECH wants to start sending you push notifications. Click allow to subscribe

Fix promised for major security flaw in OnePlus 6

This vulnerability in OnePlus 6 allows anyone with physical access to gain full control over the phone. Here’s everything you need to know about the OnePlus 6 security flaw.

By: KUL BHUSHAN
Updated on: Aug 19 2022, 23:23 IST
OnePlus 6 recently launched in India and other markets (HT Photo)

A security researcher has discovered a major security flaw in the OnePlus 6 smartphone. It allows cyber criminals with physical access to the device and a tethered PC connection to assume complete control over it.

Reported by Jason Donenfeld, president of a firm called Edge Security LLC and an XDA forum member, the flaw can be exploited if the boot image of the phone is altered using an insecure ADB (Android Debug Bridge) - a command-line tool that enables communication with a device. Jason added that he could bypass the locked bootloader without the need for USB debugging, a key requirement for altering phone software.

You may be interested in

Mobiles Tablets Laptops
OnePlus Open
  • Emerald Dusk
  • 16 GB RAM
  • 512 GB Storage
₹139,999
Buy now
OnePlus 12
  • Silver
  • 12 GB RAM
  • 256 GB Storage
₹64,999
Buy now
OnePlus 12R 256GB
  • Iron Gray
  • 16 GB RAM
  • 256 GB Storage
₹45,999
Buy now
15% OFF
OnePlus 8T
  • Aquamarine Green
  • 8 GB RAM
  • 128 GB Storage
₹28,999₹33,999
Buy now
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
4% OFF
OnePlus Pad
  • Halo Green
  • 8 GB RAM
  • 128 GB Storage
₹36,499₹37,999
Buy now
Realme Pad Mini 64GB LTE
  • Blue
  • 4 GB RAM
  • 64 GB Storage
₹23,999
Check details
9% OFF
OnePlus Pad Go LTE 256GB
  • Twin Mint
  • 8 GB RAM
  • 256 GB Storage
₹19,999₹21,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

The bootloader, an Android built-firmware, is the first thing that starts running upon booting up an Android device. A locked bootloader prevents anyone from modifying the phone's operating system. According to the researcher, the bootloader on OnePlus 6 is not entirely locked, which further enables one with the necessary tools and skills to alter the boot image and gain complete control over the phone.

Also read: Looking for a smartphone? To check mobile finder click here.

While XDA Developer first reported the vulnerability, a separate website Android Authority said it was able to replicate the security flaw. The website highlighted that one will need "physical and unsupervised access" to a OnePlus 6 phone for few minutes to exploit the vulnerability. It will also require a tethering cable and PC to load a new boot image via fastboot. Boot image is a file that features the Kernel and RAMDisk, which are key files to load the device before a file system can be loaded. ALSO READ: OnePlus 5T vs OnePlus 6

OnePlus has acknowledged the issue and promised a fix very soon. "We take security seriously at OnePlus. We are in contact with the security researcher, and a software update will be rolled out shortly," a company representative said in a note.

Security experts have advised OnePlus 6 users to be very careful with the phone until the next patch is released.

"OnePlus 6 users should be extra cautious and make sure that their device does not fall into the wrong hands, especially until a patch is released. Moreover, users are strongly advised to update their software as soon as the patch is released because in the absence of a bootloader lock, attackers might be able to modify the OS without actually having to wipe the device storage - further gaining complete root access to the device," said Ankush Johar, director at Infosec Ventures, an infrastructure security solutions service provider. ALSO READ: OnePlus 6 review

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 12 Jun, 17:09 IST

Sale

Mobiles Tablets Laptops
19% OFF
OnePlus 11
  • Titan Black
  • 8 GB RAM
  • 128 GB Storage
₹45,999₹56,999
Buy now
33% OFF
OnePlus Nord N20 SE
  • Blue Oasis
  • 4 GB RAM
  • 64 GB Storage
₹13,440₹19,999
Buy now
15% OFF
OnePlus Nord 2T 5G
  • Jade Fog
  • 8 GB RAM
  • 128 GB Storage
₹28,999₹33,999
Buy now
15% OFF
OnePlus Nord CE 3 5G
  • Aqua Surge
  • 8 GB RAM
  • 128 GB Storage
₹21,499₹25,367
Buy now
11% OFF
OnePlus Pad
  • Halo Green
  • 8 GB RAM
  • 128 GB Storage
₹33,999₹37,999
Buy now
34% OFF
Lenovo Tab P11 5G 256GB
  • Storm Grey
  • 8 GB RAM
  • 256 GB Storage
₹32,999₹50,000
Buy now
32% OFF
Samsung Galaxy Tab S6 Lite 2022
  • Chiffon Pink
  • 4 GB RAM
  • 64 GB Storage
₹20,999₹30,999
Buy now
57% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹19,999₹47,000
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
37% OFF
Asus Zenbook 14 OLED UX3402VA KN541WS Laptop
  • Ponder Blue
  • 16 GB RAM
  • 512 GB SSD
₹85,990₹135,990
Buy now
43% OFF
Asus Vivobook K15 OLED KM513UA L511WS Laptop
  • Hearty Gold
  • 16 GB RAM
  • 512 GB SSD
₹35,990₹62,990
Buy now
35% OFF
Asus ROG Strix G17 G713RM KH168WS Laptop
  • Eclipse Gray
  • 16 GB RAM
  • 1 TB SSD
₹164,990₹254,990
Buy now