In the midst of fighting tooth and nail to take on the competition, impacted "up to 40,000 s" around the globe. 4x5x1k
A French security researcher going by the name Elliot Alderson on Thursday alleged that a file in the OxygenOS beta called badword.txt helped OnePlus identify certain data from the default Clipboard app and the same to a Chinese server. The suspicious file contains keywords such as Chairman, Vice President, Deputy Director, Associate Professor, Deputy Heads, General, and Private Message among others, and its duplicate copy is found to be created in a zip file called pattern that further includes text files, including badword.txt, bracket.txt, end.txt, follow.txt, key.txt, and start.txt. All these files are claimed to be used in an "obfuscated package" that appears as an Android library from Chinese research company TeddyMobile. "According to the code, @OnePlus is sending your IMEI and the phone manufacturer to a Chinese server owned by teddymobile [sic]," the researcher tweeted.
OnePlus, on its side, responded to the allegation with a simple statement that confirms the existence of the file in the recent beta versions of OxygenOS but as a blacklist file. "There's been a false claim that the Clipboard app has been sending data to a server. The code is entirely inactive in the open beta for OxygenOS, our global operating system. No data is being sent to any server without consent in OxygenOS," the company said in a press statement, a copy of which is available on Reddit.
Additionally, OnePlus states that the open beta for HydrogenOS, which is a Chinese version of the company's OxygenOS custom ROM, contains the identified folder in order to filter out data and block competitor links in Chinese messaging services such as WeChat. This indeed means that there is no use of the filter process anywhere outside China.
Having said that, it is still a valid question that why OnePlus provided any code in the recent beta OxygenOS build that is meant exclusively for its Chinese s. The company might answer this simply by removing the code from a future build. Meanwhile, it is quite clear and obvious that the Clipboard app is not sending your data to a third-party server.
This is not the first time when OnePlus has been caught in trouble for using a sceptical code in its OxygenOS ROM. In last November, a confirmed its fix through an OTA update.
Similarly, an off late OxygenOS beta version was shipped with a Clipboard feature that was specifically designed for HydrogenOS. The company had confirmed that flaw and assured an update to remove the China-centred feature.