OnePlus 6 has a serious security flaw, and a fix is on the way

OnePlus 6

The OnePlus 6 is a fantastic smartphone, but it also has a pretty serious security flaw, as discovered by an independent security researcher – a flaw that could give tech-savvy hackers unrestricted access to your phone, if they were given physical access to it with a PC nearby.

As reported on XDA Developers, and first noticed by researcher Jason Donenfeld of Edge Security, the bootloader on the OnePlus 6 isn't as locked down as it should be – that's the part of the phone's built-in firmware that stops you replacing the OnePlus OS with whatever else you want to install instead.

It turns out that OnePlus 6 lets you boot any code you like, even when the bootloader is supposedly locked, without having to jump through the usual security hoops first – so a host of malware could be installed and you'd be none the wiser.

Don't panic

To exploit the flaw, someone would need physical access to your phone, a USB cable, and a computer, so this isn't something you're going to get hit by while your OnePlus 6 is in your pocket. Nevertheless, it looks like an oversight from the manufacturer.

The phone maker has confirmed in a statement that a fix for the bug is going to be rolling out shortly, but until then don't let your OnePlus 6 out of your sight. While the chances of someone taking advantage of the exploit are in reality very slim, we're talking about fundamental Android security measures, so it's surprising that OnePlus has missed this.

According to reports, OxygenOS 5.1.6 still includes the hack-friendly bootloader, so a patch might be included in OxygenOS 5.1.7. When we get more information on a software update, we'll let you know.

Via Android Police

David Nield
Freelance Contributor

Dave is a freelance tech journalist who has been writing about gadgets, apps and the web for more than two decades. Based out of Stockport, England, on TechRadar you'll find him covering news, features and reviews, particularly for phones, tablets and wearables. Working to ensure our breaking news coverage is the best in the business over weekends, David also has bylines at Gizmodo, T3, PopSci and a few other places besides, as well as being many years editing the likes of PC Explorer and The Hardware Handbook.

Latest in OnePlus Phones
OnePlus 13
OnePlus is ditching the Alert Slider for an iPhone-style customizable button - and I’ll be sad to see it go
OnePlus Open camera bump up close
Bad news: the OnePlus Open 2 won’t be released in 2025, OnePlus confirms
The Oppo Find N5 next to the Galaxy Z Fold 6
OnePlus Open 2 could make the Galaxy Fold 6 look old with invisible crease, according to new teaser
OnePlus 13R from the back
New OnePlus Mini 13 leak suggests its camera setup won't be as impressive as we thought
OnePlus Open
Oppo is launching the world's thinnest foldable in two weeks – and the OnePlus Open 2 should follow soon
OnePlus Open
The OnePlus Open 2 rumored to get a camera upgrade even the Samsung Galaxy S25 Ultra doesn't have
Latest in News
iOS 18 Control Center
iOS 19: the 3 biggest rumors so far, and what I want to see
Doom: The Dark Ages
Doom: The Dark Ages' director confirms DLC is in the works and says the game won't end the way 2016's Doom begins: 'If we took it all the way to that point, then that would mean that we couldn't tell any more medieval stories'
DVDs in a pile
Warner Bros is replacing some DVDs that ‘rot’ and become unwatchable – but there’s a big catch that undermines the value of physical media
A costumed Matt Murdock smiles at someone off-camera in Netflix's Daredevil TV show
Daredevil: Born Again is Disney+'s biggest series of 2025 so far, but another Marvel TV show has performed even better
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Nintendo Switch 2
A Nintendo Switch 2 FCC filing confirms Wi-Fi 6 and NFC support for the upcoming console