Monday, September 7, 2026

OnePlus Phone Critical Security Vulnerability in Default Wallpapers app Leaks Users Email Address

A critical security flaw with OnePlus device wallpaper app Shot on OnePlus leaks hundreds of user’s email address. The flaw resides in the API that used to host the photos.

The Shot on OnePlus is an application used to access photos uploaded by OnePlus users, allowing them to set wallpaper and to upload photos from the app or through the website.

9to5Google reported the bug in the API that facilitates the connectivity between the server and the OnePlus app. The API hosted on open.oneplus.net is insecure and can be accessed by anyone who has the access token.

The API is mainly used to get public photos, but the response obtained through API used by onePlus exposes sensitive data that should not be accessed publically.

It exposes the photo details, including photo code, author, email, focal-length, photo topic, uploaded location, and the uploaded time. It is unclear for how long the app is leaking the details; 9to5Google believes that it was leaking the data since its release.

Another critical vulnerability with the leak is the OnePlus gid which used to identify the user; the gid is an alphanumeric code which is used by OnePlus’s API to find photos added by the user.

The first part of the gid represents “user is from China (CN) or somewhere else (EN)” and the second part is the “unique number, like 123456”, which is easily guessable by cycling through random numbers.

9to5Google contacted OnePlus about the issue, but they haven’t received any direct responses, anyhow OnePlus made changes to the API, and for gid flaw, they added validation strings to make sure is only used by the Shot on OnePlus app, and now they obscure the email address by adding asterisks.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

OnePlus 7 Pro Fingerprint Scanner Hacked In a Minutes Using a Fake Fingerprint

OnePlus 6 Bootloader Vulnerability Could allow Boot any Image even the Bootloader is Locked

OnePlus Website Hacked and Attackers Stolen Many Customers Credit Card Details

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Hackers Can Use PEEP Chrome Extension to Steal Credentials and Execute Shell Commands

A newly identified Chromium-based post-exploitation toolkit named PEEP can...

Hackers Actively Exploiting MikroTik RouterOS MikroTrick Flaws to Take Full Control of Routers

Threat actors are actively exploiting critical vulnerabilities in MikroTik...

CrowdStrike Launches SafeMind Agentic AI Cybersecurity System Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, an AI-driven cybersecurity system developed...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Related Articles

Recent News