Published: Wed, November 15, 2017
Industry | By Dora Warner

OnePlus Phone Backdoor: Devices Shipped With Factory App That Can Root Devices

OnePlus Phone Backdoor: Devices Shipped With Factory App That Can Root Devices

Earlier this year BLU was revealed to have some serious security concerns, and even OnePlus has had issues revealed. While the root backdoor hasn't been verified in other devices yet, reports from Twitter indicate the APK was also found in Asus and Xiaomi devices.

Security researcher Robert Baptiste says the EngineerMode APK is made by Qualcomm and is meant to be used by factory staff to test phones for basic functionality before they are shipped out to the public. It was unveiled that the app potentially renders all OnePlus devices open to backdoor root access.

Kim Kardashian throws a baby shower
Kris, Kendall, Kylie and Khloé were also all in attendance, although the latter two showed no signs of their rumoured baby bumps at the event.

If it's there, anyone with physical access to your device can exploit EngineerMode to gain root access on your smartphone.

The app in question is a system app that was apparently made by Qualcomm and customized by OnePlus; it's called EngineerMode and arrives pre-installed on OnePlus devices like the OnePlus 5, 3T and 3 (you can find it yourself searching Settings Apps Menu Show system apps, and then search "EngineerMode" in the app list).

Amazon Spins off Cloud Business to Chinese Firm
Amazon's China based cloud business already had been facing tough rules due to the tight controls China has on the internet. Sinnet said in a regulatory filing on Monday the move would allow the company to comply with China's legal framework.

The developer, with the help of few cybersecurity experts, was able to discover the password and was able to root a OnePlus device with few commands. The staff member reassured users by saying that third-party apps can't gain full root privileges from EngineerMode. If this is set to "true", the app will allow root access over Android Debug Bridge, Android's command-line developer tools. Later, Pei confirmed in a blog post that OnePlus it will scale back on data collection on its devices. The app, developed by Qualcomm, has been essentially designed for OEMs to test hardware components or diagnostic tests on device.

The discoverer of the app had a problem. The developer claims that the company has left behind the software intentionally, and he will come out with the application for rooting OnePlus devices without unlocking.

Robert Woods scores twice in Rams' Week 10 blowout win
Rams have won four consecutive games following its 33-7 victory over the Houston Texans at the Los Angeles Memorial Coliseum. Fuller has appeared in six of Houston's nine games this season, catching 17 passes for 326 yards and seven touchdowns.

OnePlus did not immediately respond to a request for comment.

Like this: