Subject: 答复: Two security issues on latest OxygenOS allowing any app to run code as root From: Security To: Rasmus Moorats Created at: Wed, May 20, 2026 at 11:14 AM Hi Rasmus, Thank you very much for submitting this valid vulnerability report. Our security team has completed verification and scheduled it for remediation. Regarding your intention to publicly release relevant vulnerability information on your own after we finish the fix, we hereby clarify our official position in accordance with our public Responsible Security Disclosure Policy: https://security.oneplus.com/en/responsibleDisclosure 1. Our team holds the exclusive final right of vulnerability disclosure In accordance with all clauses of our official disclosure policy, for all security vulnerabilities submitted to us, regardless of submission channels and remediation status, we retain full decision-making power over the public release of all relevant content including technical details, exploitation methods and risk mechanisms. Even after full rollout of fixed versions, individual researchers are not entitled to independently compile and publish complete vulnerability analysis reports or technical details, which is inconsistent with our official security disclosure specifications. 2. Explanation on relevant EU regulations The core purpose of EU cybersecurity regulations is merely to urge manufacturers to accept vulnerability reports and complete timely fixes to protect user security. Such regulations only confirm researchers’ legitimate right to submit vulnerabilities, but do not grant researchers the permission to disclose unauthorised vulnerability content without prior consent from the affected enterprise, hence they cannot serve as valid grounds for your independent public disclosure. 3. Vulnerability scope & official submission guidelines This vulnerability is applicable to all series of OPPO terminal products with universal security risks. Apart from our official security platform, you may also resubmit the complete vulnerability report via the HackerOne platform. We recognize the validity of submissions made through HackerOne. Once your report passes our internal review, we will issue corresponding official bug bounties in accordance with standard rating rules. 4. Our official recognition arrangement We fully respect your research contributions. After the vulnerability is fully fixed and security updates are fully released, we will arrange unified official announcements and public acknowledgements, and credit your name on our official security honour list. This fully satisfies your needs for industry recognition and public exposure, and there is no need for you to release relevant content privately. Kindly be reminded that without our official written authorization, any unauthorized disclosure of vulnerability technical details whether the vulnerability is fixed or not will not only violate responsible disclosure principles, but we will also pursue relevant legal liabilities in accordance with applicable laws. We highly recognize your professional security research capabilities. We sincerely hope you will abide by industry universal norms and our official security regulations, and conduct vulnerability submission and security cooperation through standard official channels to jointly maintain a sound cybersecurity research ecosystem. Best regards, One SRC Team