Skip to main content

An app installed on OnePlus devices left root access open, poses potential security threat

One of the biggest concerns with buying from smaller brands that many often overlook is security. Earlier this year BLU was revealed to have some serious security concerns, and even OnePlus has had issues revealed. Now, another potential threat has arisen on OnePlus devices as an app on several of the company’s phones has been revealed to carry root access.

A developer recently discovered that an app installed on OnePlus devices (OnePlus 3, 3T, 5 according to Android Police) called “EngineerMode.” This app is used by OnePlus to ensure that a device is working properly before it leaves the factory. However, it also holds a backdoor which is capable of root access, even if the device has not been unlocked.

Root access was still hidden behind a password, but once that was cracked, that developer was able to obtain root access on the phone. That developer has plans to release an app which exploits this method as a way to give OnePlus users the easiest root method of all time, but don’t expect that to last long.

This exploit is just that, an exploit in the phone’s security. While the risk is low since enabling root requires ADB, it still poses a threat to users. OnePlus has been alerted to the exploit and CEO Carl Pei has confirmed that the company is looking into it. Hopefully, that ends with an update that removes the app.

https://twitter.com/getpeid/status/930197107255992321


Check out 9to5Google on YouTube for more news:

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Google — experts who break news about Google and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Google on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel