The OnePlus phone defect could let the devices send unwanted text messages – so take care of who you ping


  • CVE-2025-10184 allows attackers Read and send SMS, including 2FA codes
  • Vulnerability affects oxygenos 12 to 15 versions, used on many OnePlus devices
  • Rapid7 disclosed a flaw after failed contact; OnePlus has not yet published a corrective

Vulnerability in the software used in OnePlus smartphones could allow threat actors to send SMS messages on behalf of the victim, experts warned.

Worse still, this allows them to read the content of SMS, including multi-factor authentication codes, in cases where SMS is configured as the second second secondary layer of choice, researchers in rapid7 reveaké.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top