OnePlus 10T Reaches End of Security Support, Leaving Devices Unpatched
What Happened — OnePlus announced that security updates for the OnePlus 10T smartphone have officially ended. Owners can no longer receive patches for newly discovered vulnerabilities, and the device will not receive any further security fixes.
Why It Matters for Compliance & Audit Readiness
- Unsupported endpoints create a control gap in SOC 2 CC6.1 (System Operations) and CC7.2 (Change Management) because you cannot demonstrate ongoing protection of the device.
- Continuous‑compliance programs require evidence that all assets handling CUI remain within a supported lifecycle; an out‑of‑support phone undermines that evidence.
- Verisq’s Control Mapping capability lets you map endpoint‑management policies to SOC 2 controls and collect continuous proof that unsupported devices are removed or isolated.
Who Is Affected — Consumer‑grade smartphones used in BYOD programs across all sectors, especially organizations that permit personal devices for work (e.g., finance, healthcare, tech SaaS).
Recommended Actions
- Inventory all mobile endpoints and flag any that have reached end‑of‑support.
- Update your asset‑lifecycle policy to require retirement or replacement of unsupported devices within a defined timeframe.
- Map the retirement process to SOC 2 CC6.1 and CC7.2, and capture evidence (e.g., device de‑provision logs) for audit readiness.
Technical Notes — The support termination applies to the OnePlus 10T model released in 2022; no specific CVE is cited, but the device will miss patches for any future vulnerabilities discovered in its Android base or OnePlus‑specific components. Source: TechRepublic