Get the latest tech news
Flaw in OnePlus phones lets apps read your texts, fix rolling out soon
The flaw lets apps snoop on your SMS/MMS without permission, putting two-factor codes at risk.
Researchers at Rapid7 found a flaw, identified as CVE-2025-10184, that lets harmful apps read and send your text messages without your permission. In practice, this means an attacker could intercept sensitive texts like two-factor authentication (2FA) codes or even send out messages on your behalf, opening the door to account takeovers and fraud. The company added new components called PushMessageProvider, PushShopProvider, and ServiceNumberProvider, but did not set proper limits on write permissions.
Or read this on Android Central