Discover the impact of CVE-2017-8850 on OnePlus devices including One, X, 2, 3, and 3T. Learn about the vulnerability allowing attackers to switch ROMs and exploit patched vulnerabilities.
A vulnerability has been discovered on multiple OnePlus devices including OnePlus One, X, 2, 3, and 3T due to a lenient updater-script in the OnePlus OTA images and the use of the same OTA verification keys for both ROMs. This vulnerability allows attackers to install HydrogenOS over OxygenOS and vice versa, even on locked bootloaders, expanding the attack surface.
Understanding CVE-2017-8850
This CVE highlights a security issue on various OnePlus devices that can be exploited by attackers during the update process.
What is CVE-2017-8850?
The vulnerability arises from the lenient updater-script in OnePlus OTA images and the shared OTA verification keys between ROMs, enabling attackers to switch between ROMs and exploit vulnerabilities across different images.
The Impact of CVE-2017-8850
Technical Details of CVE-2017-8850
This section provides detailed technical insights into the vulnerability.
Vulnerability Description
The vulnerability allows for the installation of different ROMs on OnePlus devices, enabling the exploitation of patched vulnerabilities across ROMs.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting devices from CVE-2017-8850 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates