Android security issue: the VPN flaw that can expose your IP address

Android security issue: the VPN flaw that can expose your IP address

A newly discovered vulnerability on Android could allow malicious applications to reveal your smartphone’s real IP address, even if you are using a VPN. A flaw in the system allows data packets to escape the secure tunnel, jeopardizing user privacy. Find out how this flaw works and why it could affect all Android devices.

The essentials to remember

  • An Android flaw allows applications to reveal a smartphone’s real IP address, even with an active VPN.
  • The issue is related to a network connection maintenance feature, which can be hijacked by malicious applications.
  • Google has not yet released a fix, although the issue was reported last May.

Imagine browsing the Internet, confident that your VPN is protecting your online identity. But then an app you installed on your smartphone manages to bypass this security, revealing your true IP address. This is the puzzle Android users face due to a recently identified flaw. This issue, which potentially affects all Android devices, illustrates the ongoing challenges of digital security.

Armin Šupuk and the discovery of the Android flaw

Independent researcher Armin Šupuk highlighted a critical vulnerability in the Android system. His discovery, shared by Mullvad, shows how an application can exploit a native Android function to send data packets outside the VPN tunnel.

This issue does not stem from a VPN defect but from an Android feature that ensures network connections remain active. By using this function, an application can transmit packets to a server controlled by an attacker, thus revealing the smartphone’s IP address.

How the network connection maintenance system works

Android uses a mechanism called keep-alive, which regularly sends small packets on port 4500 to keep the network connection active. This task can be delegated to the phone’s Wi-Fi chip to save energy. However, this alternative path allows packets to escape VPN control, thus revealing the device’s real IP address.

Šupuk demonstrated this leak on a Pixel 8 Pro using Android 16, and tests on other devices like Samsung and Nothing confirmed the issue, ruling out the hypothesis of a defect related to a specific manufacturer.

Reactions and resolution prospects

Mullvad studied a temporary solution, but it proved ineffective. The Wi-Fi chip can only handle a limited number of simultaneous keep-alive connections. To protect users, the VPN client should preempt all these connections, but this would involve sending packets outside the tunnel, which goes against the purpose of a VPN.

Despite efforts to alert Google, the company has not yet released a fix. Šupuk’s report was classified as a duplicate of an already known issue, but no solution has been announced since. However, GrapheneOS, an Android-based operating system, has confirmed that it is working on a fix for this flaw.

Google and Android system security

This flaw raises questions about Google’s responsiveness to security threats. Although vulnerability discovery reward programs exist, the slow implementation of fixes can leave users exposed. With the increase in cyberattacks, it is urgent for tech companies to adopt proactive measures to secure their systems.

The challenges of mobile security in the digital age

Mobile device security has become a major issue with the proliferation of applications and the growing reliance on smartphones. Cybersecurity companies, such as Kaspersky and McAfee, warn against the potential implications of these flaws. A holistic approach integrating regular updates and increased user vigilance is essential to ensure data privacy and security.

FAQ on the Android flaw and VPN

What causes this IP address leak on Android?

The leak is caused by an Android function that keeps the network connection active, allowing data packets to bypass the VPN tunnel.

Why hasn’t Google fixed this flaw yet?

Although the flaw was reported to Google, it was classified as a duplicate of a known issue, without a fix being announced so far.

How can users protect themselves against this flaw?

For now, there is no definitive solution. Users should be cautious about the applications they install and closely follow the security updates offered by Android.

Does GrapheneOS have a solution to offer?

Yes, GrapheneOS has confirmed that it is working on a fix for this flaw, thus enhancing the security and privacy of devices using their operating system.