OTA Update Exploit in OnePlus Smartphones Exposes Users to Potential Attacks
CVE-2017-8850
What is CVE-2017-8850?
A vulnerability exists in certain OnePlus smartphone models due to a configuration flaw in the OTA update process. This flaw allows attackers to exploit the lenient updater-script in OTA images, enabling unauthorized installations of HydrogenOS over OxygenOS and vice versa, even on locked bootloaders. Such an exploit facilitates the circumvention of vulnerabilities that have been patched in one operating system but remain unaddressed in the other. The update process is susceptible to man-in-the-middle (MiTM) attacks as it lacks TLS encryption, further putting users at risk. Additionally, physical access to the device allows an attacker to utilize 'adb sideload' methods to push compromised updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
