• Sources: primary, HN discussion
  • Summary: Mullvad reports that an app with no special permission can ask the platform for a hardware-offloaded NAT keep-alive, which the Wi-Fi or cellular chip then sends as UDP to port 4500 on any host, bypassing the check that all traffic must traverse the VPN and exposing the real IP address. Mullvad states the researcher's report to the Android Vulnerability Reward Program was closed without action, that a proper fix requires an Android system change, and that GrapheneOS is working on its own. Mullvad names no affected Android version range, so the version scope is not stated by the source. Mullvad states it will not ship the one theoretical mitigation, exhausting the hardware keep-alive slots, because that still sends packets outside the tunnel and a malicious app can claim a slot before the VPN app starts.
  • Why it matters: Android's kill switch does not hold against an unprivileged app on an unpatched system, and no platform fix is committed.
  • Follow-up: Whether Android ships a system-level fix, and whether GrapheneOS lands its own mitigation.

send feedback on this story