A newly discovered vulnerability on Android could allow malicious applications to reveal your smartphone’s real IP address, even if you are using a VPN. A flaw in the system allows data packets to escape the secure tunnel, jeopardizing user privacy. Find out how this flaw works and why it could affect all Android devices.
The essentials to remember
Imagine browsing the Internet, confident that your VPN is protecting your online identity. But then an app you installed on your smartphone manages to bypass this security, revealing your true IP address. This is the puzzle Android users face due to a recently identified flaw. This issue, which potentially affects all Android devices, illustrates the ongoing challenges of digital security.
Independent researcher Armin Šupuk highlighted a critical vulnerability in the Android system. His discovery, shared by Mullvad, shows how an application can exploit a native Android function to send data packets outside the VPN tunnel.
This issue does not stem from a VPN defect but from an Android feature that ensures network connections remain active. By using this function, an application can transmit packets to a server controlled by an attacker, thus revealing the smartphone’s IP address.
Android uses a mechanism called keep-alive, which regularly sends small packets on port 4500 to keep the network connection active. This task can be delegated to the phone’s Wi-Fi chip to save energy. However, this alternative path allows packets to escape VPN control, thus revealing the device’s real IP address.
Šupuk demonstrated this leak on a Pixel 8 Pro using Android 16, and tests on other devices like Samsung and Nothing confirmed the issue, ruling out the hypothesis of a defect related to a specific manufacturer.
Mullvad studied a temporary solution, but it proved ineffective. The Wi-Fi chip can only handle a limited number of simultaneous keep-alive connections. To protect users, the VPN client should preempt all these connections, but this would involve sending packets outside the tunnel, which goes against the purpose of a VPN.
Despite efforts to alert Google, the company has not yet released a fix. Šupuk’s report was classified as a duplicate of an already known issue, but no solution has been announced since. However, GrapheneOS, an Android-based operating system, has confirmed that it is working on a fix for this flaw.
This flaw raises questions about Google’s responsiveness to security threats. Although vulnerability discovery reward programs exist, the slow implementation of fixes can leave users exposed. With the increase in cyberattacks, it is urgent for tech companies to adopt proactive measures to secure their systems.
Mobile device security has become a major issue with the proliferation of applications and the growing reliance on smartphones. Cybersecurity companies, such as Kaspersky and McAfee, warn against the potential implications of these flaws. A holistic approach integrating regular updates and increased user vigilance is essential to ensure data privacy and security.
What causes this IP address leak on Android?
The leak is caused by an Android function that keeps the network connection active, allowing data packets to bypass the VPN tunnel.
Why hasn’t Google fixed this flaw yet?
Although the flaw was reported to Google, it was classified as a duplicate of a known issue, without a fix being announced so far.
How can users protect themselves against this flaw?
For now, there is no definitive solution. Users should be cautious about the applications they install and closely follow the security updates offered by Android.
Does GrapheneOS have a solution to offer?
Yes, GrapheneOS has confirmed that it is working on a fix for this flaw, thus enhancing the security and privacy of devices using their operating system.