OnePlus has confirmed that phones running Oxygen OS 12, 14, and 15 are affected by a major SMS vulnerability that has no fix right now.
CVE-2025-10184 lets attackers read and send SMS, including 2FA codes Vulnerability affects OxygenOS versions 12 to 15, used across many OnePlus devices Rapid7 disclosed flaw after failed contact; ...
A vulnerability in the software used in OnePlus smartphones could allow threat actors to send SMS messages on behalf of the victim, experts have warned.