Hacker News·3 min read·hard

Another way to leak traffic on Android has been discovered

M
mhitza
Another way to leak traffic on Android has been discovered
AI Summary

A security vulnerability in the Android network stack allows malicious apps to bypass VPN tunnels by using hardware-offloaded UDP keep-alive connections. This leak exposes a user's real IP address, and researchers suggest Google is unlikely to patch the issue, leaving mitigation to third-party developers.

Why it matters

This flaw undermines the privacy and security guarantees of VPNs on Android devices, potentially exposing users to tracking and surveillance.

Dive DeeperCreate a free account to unlock

A newly discovered leak in Android allows any app to send traffic outside the VPN tunnel.

Yet another leak was recently discovered in the Android network stack that allows a malicious app to send traffic outside the VPN tunnel, even when "Block all connections without VPN" is active.

Having traffic leak outside the tunnel means your real IP address becomes visible on the Internet, which could potentially be used for tracking or surveillance purposes.

The malicious app does not need any special permission to perform this attack.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyscience

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in