A critical security vulnerability has been discovered in OnePlus smartphones running OxygenOS versions 12, 14, and 15. The flaw, tracked as CVE-2025-10184, enables unauthorized applications to access SMS and MMS messages without requiring permissions or alerting users. The discovery raises particular concern given OnePlus’s previous focus on security features, including the company’s implementation of facial recognition authentication in earlier devices.
The vulnerability affects numerous OnePlus devices, including the OnePlus 8T, OnePlus 10 Pro 5G, and likely extends to newer models such as the OnePlus 12, 13, and OnePlus Open foldable. The security flaw originates from a permission bypass in the internal content provider ‘com.oneplus.provider.telephony,’ which exposes messaging data without proper authorization checks. The vulnerability is especially significant for OnePlus devices, which have historically featured advanced security measures including in-display fingerprint sensors for device authentication.
The National Vulnerability Database has assigned this flaw a severity rating of 8.2, indicating high risk. The vulnerability requires no user interaction or special permissions for exploitation, and users receive no notifications when their SMS/MMS data is accessed. The security breach is particularly concerning given recent FBI and CISA warnings about vulnerabilities in SMS-based authentication systems.
Cybersecurity firm Rapid7, which discovered and disclosed the vulnerability in September 2025, reports that the flaw has existed since the release of OxygenOS 12 in December 2021. “The issue stems from the fact that sensitive internal content providers are accessible without permission, and are vulnerable to SQL injection,” explained a Rapid7 researcher. The vulnerability follows a broader pattern of content provider security issues that have affected various mobile platforms and services.
“We acknowledge the recent disclosure of CVE-2025-10184 and have implemented a fix. This will be rolled out globally via software update starting from mid-October. OnePlus remains committed to protecting customer data and will continue to prioritize security improvements,” OnePlus stated in an official announcement.
Security experts recommend that users avoid installing applications from unknown sources until the patch deployment is complete. Additionally, users are advised to consider switching from SMS-based two-factor authentication to app-based alternatives to enhance security. The recommendation matches current industry trends, as major technology companies like Google are increasingly moving away from SMS-based authentication in favor of more secure methods.
Sources: Android Authority, The Register, 9to5Google, News18, Rapid7 Blog, National Vulnerability Database