CVE-2025-10184: Oneplus Oxygenos

High severity, CVSS 8.2. EPSS: 3.8% chance of exploitation in the next 30 days.

The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks. The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.

Affected products

  • Oneplus Oxygenos: from 12, before 13 (fixed in 13); from 13, before 14 (fixed in 14); from 14, before 15 (fixed in 15); from 15, before 16 (fixed in 16)

Published 2025-09-23. Last modified 2026-06-17.