OnePlus OxygenOS Telephony provider permission bypass
Published Sep 23, 2025
8.2
HIGHCVSS 4.0
EPSS 3.81%
Description
The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks.
The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.
Affected products
-
- Version 12.*StatusaffectedConstraints-
- Version 13.*StatusaffectedConstraints-
- Version 14.*StatusaffectedConstraints-
- Version 15.*StatusaffectedConstraints-
- Version 11.*StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4b7439a28b6c866/68d168a6930d015d43a6b588/CVE-2025-10184_PoC.zip exploit
- https://www.rapid7.com/blog/post/cve-2025-10184-oneplus-oxygenos-telephony-provider-permission-bypass-not-fixed/ exploitthird-party-advisorytechnical-description
| Link | Providers | Tags |
|---|---|---|
| https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/bltd4b7439a28b6c866/68d168a6930d015d43a6b588/CVE-2025-10184_PoC.zip | exploit | |
| https://www.rapid7.com/blog/post/cve-2025-10184-oneplus-oxygenos-telephony-provider-permission-bypass-not-fixed/ | exploitthird-party-advisorytechnical-description |
Change history (0)
No recorded changes yet.