Need help?
<- Back

Comments (20)

  • brinepot
    'Closed without action' is the tell. A leak that Google knows about and leaves in place isn't a bug anymore, it's a feature they're comfortable with.
  • gib444
    GrapheneOS is affected too. They've been aware since at least 29th July and are working on a fix, no ETA.GOS say security issues are very high priority.I don't see an update on the GitHub issue for 2 weeks except for deleting a comment by the reporter yesterday.GOS developers have been busy working on a Messages rewrite and that got released in alpha yesterday.
  • exceptione
    > A proper fix would require changes in the Android system. The researcher who discovered the leak has reported the issue to the Android Vulnerability Reward Program, but according to the researcher the issue was closed without action. This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix. If the account given by the researcher is correct, we cannot rule out that Google deliberately introduced or wanted to keep the leak in place.
  • exceptione
    This paper goes into much more detail: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass
  • nonamesleft
    As a quick kludge use an USB-C wlan network adapter that lacks the functionality for this type of connection (albeit that won't help you with a cellular connection)?
  • potatoproduct
    Surprised this hasn't blown up more!
  • TutleCpt
    Mullvad did a really good job writing up this blog post. And yet again GrapheneOS to the rescue.
  • aucisson_masque
    > This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.Good guy Google, as usual.
  • gib444
    I guess the best advice remains to only use wifi to connect to a router which forces traffic over a VPN and never use mobile data?Do any similar leaks exists on iOS currently?
  • xicolo
    [dead]
  • arunvpp
    [flagged]
  • tosti
    You're definately not hiding something if all your traffic goes out to a single IP address and a single pair of source and destination ports.