<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OnePlus (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/oneplus.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/oneplus-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OnePlus (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:09 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2023-26309 – A remote code execution vulnerability in the webview component of OnePlus Store ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26309</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26309</guid>
    <pubDate>Thu, 10 Aug 2023 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26309</strong></p>
  <p>A remote code execution vulnerability in the webview component of OnePlus Store app.</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26309">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-11105 – The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition befo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-11105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-11105</guid>
    <pubDate>Thu, 03 Aug 2017 08:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-11105</strong></p>
  <p>The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-11105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10370 – An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10370</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10370</guid>
    <pubDate>Thu, 11 May 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10370</strong></p>
  <p>An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10370">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-5626 – OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5626</guid>
    <pubDate>Sun, 12 Mar 2017 05:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-5626</strong></p>
  <p>OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding the 'OEM Unlocking' checkbox, without user confirmation and without a factory reset. This allows for persistent code execution with high privileges (kernel/root) with complete access to user data.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-5624 – An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5624</guid>
    <pubDate>Sun, 12 Mar 2017 05:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-5624</strong></p>
  <p>An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by issuing the 'fastboot oem disable_dm_verity' command. Having dm-verity disabled, the kernel will not verify the system partition (and any other dm-verity protected partition), which may allow for persistent code execution…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-5554 – An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-5554</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-5554</guid>
    <pubDate>Mon, 23 Jan 2017 07:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-5554</strong></p>
  <p>An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot, where an attacker with ADB access can issue the adb reboot bootloader command. Then, the attacker can put the platform's SELinux in permissive…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-5554">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
