Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability (opens in a new tab)
Why readA live, unpatched session takeover in an app preinstalled on the OnePlus 13R, published after the vendor stopped giving a remediation timeline.
Doyensec targeted the OEM applications shipped on the OnePlus 13R and found a flaw in one of them that allows takeover of a user session. The vendor did not commit to a fix schedule through the disclosure window, so the researchers published without a patch available. Beyond the bug itself, the write up is a concrete case study in what happens when a bug bounty relationship breaks down on the vendor side.