CVE-2026-22078: Oppo O+ Connect

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

Affected products

  • Oppo O+ Connect: version 16.0.33 only

Published 2026-06-29. Last modified 2026-06-29.