In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://alephsecurity.com/vulns/aleph-2017006 | third party advisory technical description |