29
posted ago by winn ago by winn +29 / -0

TL;DR

  • security researcher @cybaqkebm found a bug on Android
  • the bug allows apps to circumvent VPN tunnels, leaking user data
  • the bug was reported to Android, with a proposed fix
  • Android sais it wouldn't fix it
  • The bug report mysteriously disappeared
  • GrapheneOS already released a patched version
  • advanced users can manually patch their Androids via USB debugging (adb code)

A new VPN leak that allows any app to leak traffic outside the VPN tunnel has recently been discovered by @cybaqkebm

Read more here:

https://mullvad.net/en/blog/any-app-on-recent-android-versions-can-leak-certain-traffic

https://x.com/vinibarbosabr/status/2054164015207621109