Junglewise Threat Intelligence

CVE-2026-22078: OPPO O+ Connect privilege escalation in IPC service

CVE-2026-22078 · Severity: high · CVSS 7.3 · Published 2026-06-29

Executive brief

A security vulnerability exists in OPPO's O+ Connect application, which is used for device connectivity and synchronization. Because the application fails to verify the identity of other programs trying to communicate with it, a malicious app installed on the same device could gain unauthorized permissions. This could allow an attacker to perform sensitive actions or disrupt the device's normal operations.

Technical details

A privilege escalation vulnerability exists in the OPPO O+ Connect application due to missing authentication in its Inter-Process Communication (IPC) service. The flaw, classified as CWE-266 (Incorrect Privilege Assignment), allows a locally installed malicious application to interact with the O+ Connect IPC channel without proper authorization. By exploiting this lack of client verification, an attacker can execute sensitive functions or escalate their privileges on the device. The vulnerability requires local access and some level of user interaction to be successfully exploited. Version 16.0.33 is confirmed to be affected.

Affected products

  • OPPO O+ Connect 16.0.33

Timeline

  • 2026-06-29: advisory: NVD publication date
  • 2026-06-29: disclosed: OPPO security advisory published

References

Related threats