AntiMalware•September 10, 2026•🇷🇺Translated from Russian

OnePlus 13R Preinstalled Account App Leaks Cloud Session Tokens to Any App Declaring Required Permission

Researchers from Doyensec have discovered a vulnerability in the preinstalled software on the OnePlus 13R that allows a third-party application to steal a valid OnePlus Cloud session token. The issue resides in the com.oneplus.account application responsible for managing authentication to the manufacturer’s services.

The exposed component OPAccountProvider is protected by the permission com.oneplus.account.READ_ACCOUNT_INFO. However, developers failed to set protectionLevel="signature", which would have restricted access exclusively to applications signed by OnePlus. As a result, any third-party application can simply declare the same permission in its manifest and query the provider.

Upon receiving a specific command, the provider returns the active OnePlus Cloud session token. No pop-up dialogs, security warnings, or explicit user consent are required. In the initial proof-of-concept, researchers used the stolen token to call OnePlus Cloud APIs and modify the victim’s personal data.

Doyensec reported the vulnerability to OnePlus on 30 December 2025. The vendor acknowledged the issue, rated its severity as high, and paid the researchers $720 in March 2026. A patch, however, has been slow to arrive.

In September, re-testing on firmware CPH2691_16.0.10.500(EX01) confirmed that an untrusted application can still obtain the token and that the regional API continues to accept it. Full reproduction of account data changes for US and EMEA accounts was no longer possible due to service-side modifications, meaning token leakage remains while complete account takeover on the latest version has not been verified.

Users are recommended to avoid installing applications from untrusted sources and to monitor for updates. OnePlus simply needs to add the single word “signature” to the permission definition to resolve the exposure.

Related articles

Security NEXT•Vulnerabilities & Exploits

Apache WSS4J Library Addresses Seven Vulnerabilities Including Authentication Bypass Flaws

The Apache WSS4J library, used to apply WS-Security to SOAP messages in Java environments, has received updates fixing seven vulnerabilities. The development team disclosed multiple security advisories on September 30, 2026, covering the issues. Three vulnerabilities received an Important severity rating: CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616. CVE-2026-88920 allows authentication bypass in the DOM security processor by injecting attacker-controlled keys into crafted unsigned sender-vouches SAML assertions. CVE-2026-89238 stems from improper handling of encryption headers, enabling attackers to force plaintext elements to be treated as decrypted headers and bypass security policies. The remaining four vulnerabilities were also resolved in the same coordinated update release.

Security NEXT•Vulnerabilities & Exploits

US Authorities Warn of Active Exploitation of Apple CoreGraphics and Cisco SD-WAN Vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two newly identified vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-86950 affects Apple iOS, iPadOS, and macOS through a flaw in the CoreGraphics framework that allows out-of-bounds memory writes and potential arbitrary code execution. CVE-2026-76504 impacts Cisco Catalyst SD-WAN Manager, enabling unauthenticated attackers to gain administrative access due to improper URI encoding handling in the API. Federal agencies must remediate both issues within three days of their respective catalog additions. CISA also requires organizations to check for signs of compromise in addition to applying patches. The alerts highlight ongoing risks to widely deployed Apple operating systems and enterprise SD-WAN infrastructure.

Security NEXT•Vulnerabilities & Exploits

Cisco Patches Critical Zero-Day Authentication Bypass in Catalyst SD-WAN Manager

Cisco Systems has released security updates to address a critical zero-day vulnerability in Cisco Catalyst SD-WAN Manager that allows attackers to bypass authentication and gain remote administrator access. The flaw, tracked as CVE-2026-76504, stems from improper URI encoding handling in HTTP requests targeting specific APIs. With a CVSS v3.1 base score of 9.8, the issue is rated Critical and has already been exploited in real-world attacks confirmed by Cisco in September 2026. The company published its security advisory on September 30, 2026, and strongly recommends immediate updates to the fixed releases. Organizations are also advised to restrict API access to trusted sources while applying the patches.

Hispasec•Vulnerabilities & Exploits

Hackers Exploit Two Critical Citrix NetScaler Zero-Days to Deploy Web Shells and Enable Lateral Movement

Two critical zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, are being actively exploited in the wild to achieve unauthenticated remote code execution. Attackers deploy password-protected PHP web shells such as WHIPSHOT and use the Python-based SLAPSHOT tunneling tool for lateral movement inside targeted networks. The flaws affect NetScaler ADC and NetScaler Gateway appliances with default configurations, and one requires DTLS enabled on VPN vServers. Citrix has released patches for versions 13.1-64.23 and 14.1-73.37, while CISA added the issues to its KEV catalog with a September 30, 2026 remediation deadline for U.S. federal agencies. Organizations are advised to hunt for indicators including modified httpd.conf entries, anomalous setuid permissions on /bin/sh, and suspicious files in /var/netscaler/logon/LogonPoint/custom before applying updates.