← Latest briefing

Technology

Android vulnerability report claims apps can bypass active VPN tunnels

Hacker News reports that an unpatched Android flaw reportedly allows apps to transmit traffic outside VPN protections.

The short version

  • A reported Android vulnerability permits apps without special permissions to send traffic outside active VPN tunnels.[Hacker News]
  • The bypass reportedly circumvents the system setting designed to block all non-VPN connections.[Hacker News]
  • A researcher stated the Android Vulnerability Reward Program closed the report without remediation, while GrapheneOS is developing a fix.[Hacker News]

Key facts

  • A reported vulnerability in Android allows applications without special permissions to route traffic outside VPN tunnels.[Hacker News]
  • The leak functions even when the system setting to block connections without a VPN is turned on.[Hacker News]
  • The mechanism relies on offloading keep-alive UDP connections to Wi-Fi or cellular hardware chips.[Hacker News]
  • GrapheneOS is aware of the reported flaw and is preparing a fix.[Hacker News]

What remains uncertain

  • Whether Google plans any upstream remediation remains unconfirmed after the researcher stated the Android Vulnerability Reward Program closed the report without action.[Hacker News]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.