The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks.
The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Google
Google android Oneplus Oneplus oxygenos |
|
Vendors & Products |
Google
Google android Oneplus Oneplus oxygenos |
Tue, 23 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 23 Sep 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The vulnerability allows any application installed on the device to read SMS/MMS data and metadata from the system-provided Telephony provider without permission, user interaction, or consent. The user is also not notified that SMS data is being accessed. This could lead to sensitive information disclosure and could effectively break the security provided by SMS-based Multi-Factor Authentication (MFA) checks. The root cause is a combination of missing permissions for write operations in several content providers (com.android.providers.telephony.PushMessageProvider, com.android.providers.telephony.PushShopProvider, com.android.providers.telephony.ServiceNumberProvider), and a blind SQL injection in the update method of those providers. | |
Title | OnePlus OxygenOS Telephony provider permission bypass | |
Weaknesses | CWE-862 CWE-89 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: rapid7
Published: 2025-09-23T13:02:47.366Z
Updated: 2025-09-23T13:26:55.804Z
Reserved: 2025-09-09T14:58:29.247Z
Link: CVE-2025-10184

Updated: 2025-09-23T13:26:42.610Z

Status : Awaiting Analysis
Published: 2025-09-23T13:15:27.770
Modified: 2025-09-24T18:11:24.520
Link: CVE-2025-10184

No data.