Technology

Samsung, Xiaomi, Oppo and OnePlus Phones Hit by OEM Security Flaws

Published: 15 September 2026 · 1 min read

What Happened

A security researcher demonstrated a technique, dubbed“OEMpocalypse Now,” that reportedly allows an ordinary Android app with no special permissions to gain root access on flagship devices from Samsung, Xiaomi, Oppo, OnePlus and Realme. According to the researcher, the vulnerabilities are not in core Android itself but in manufacturer-added software layers and OEM-specific drivers that have deep access to the operating system.

Key Takeaways

If validated and exploited in the real world, such vulnerabilities could allow attackers to bypass Android’s security protections and take near-complete control of affected devices. The research highlights a growing concern that custom software developed by phone manufacturers may introduce security risks even when devices are running the latest Android security updates. The researcher has not publicly released exploit code, and further technical details are expected in future disclosures.

Sources

Cybernews