A new vulnerability in Android allows apps to bypass a Virtual Private Network (VPN) and expose a device's real IP address, even when the system is configured to block all traffic outside the encrypted tunnel. This flaw does not stem from the VPN itself but from an Android function that periodically sends network "keep-alive" signals to maintain active connections. Independent researcher Armin Šupuk, working with privacy-focusedVPN provider Mullvad, discovered that malicious apps can exploit this mechanism to send data outside the tunnel without needing special permissions or root access. Once the packets leave the device, an attacker's server can then capture the device's real IP address, undermining the privacy benefits of the VPN.
Normally, Android ensures that all traffic from apps goes through the VPN tunnel or is blocked if the tunnel is unavailable. This process involves sending small UDP packets on port 4500 at regular intervals to maintain a connection with the network, known as NAT-T (Network Address Translation Traversal). Android can delegate this task to the Wi-Fi chip to save system resources. However, an app can request the system to send these packets to a server it controls. If Android uses the Wi-Fi chip to send these packets, the data bypasses the software checks that enforce the VPN, allowing the packets to leave the device directly and reveal the real IP address to the attacker’s server.
Šupuk confirmed the vulnerability on a Pixel 8 Pro running Android 16 via Wi-Fi, even with a permanentVPN and a "kill switch" enabled to block traffic if theVPN failed. Similar tests on Samsung and Nothing devices showed that the flaw is not specific to a particular device or manufacturer, but rather a systemic issue within Android itself. This suggests that the problem lies in the Android operating system rather than a flaw in individual hardware or software implementations.
Until a permanent fix is available, a temporary workaround has been proposed. Since the Wi-Fi chip can handle only a limited number of keep-alive connections, theVPN client could theoretically monopolize all available connections before theVPN is activated, preventing malicious apps from using one. However, this approach is counterintuitive forVPN software and may not always work, as a malicious app might already have reserved a connection. As a result, a system-level patch from Google is needed, but such a fix has not yet been released. Šupuk reported the issue to Google's Android Vulnerability Rewards Program in May, but it was labeled as a duplicate of an existing known issue with no announced fix. In contrast, GrapheneOS, a privacy-focused version of Android, has confirmed the bug and plans to address it in the near future.
Android Vulnerability Exposes Real IP Addresses Despite Active VPNs
AI-rewritten from original reportingHow it works
androidvpnip-leaksecurityprivacyexploit
Original sources:
- 🇫🇷Clubic



