PatchSiren

Oneplus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oneplus CVE published 2017-01-23

CVE-2017-5554

CVE-2017-5554 is a OnePlus ABOOT issue in OxygenOS on OnePlus 3 and 3T devices before 4.0.2. If an attacker can get the device into fastboot mode—either physically during boot or through ADB access—they can issue a fastboot command that switches SELinux into permissive mode, significantly reducing Android security controls.