Another way to leak traffic on Android has been discovered
77 points by mhitza 14 hours ago | 8 comments
exceptione 2 hours ago
This paper goes into much more detail: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass
replynonamesleft 2 hours ago
As a quick kludge use an USB-C wlan network adapter that lacks the functionality for this type of connection (albeit that won't help you with a cellular connection)?
replyexceptione 2 hours ago
Regarding cellular connection, the proof of concept presented here only works on wifi: https://github.com/GrapheneOS/os-issue-tracker/issues/8617
replyI have a hunch this leak is bound to wifi hardware only, for details: https://supuk.ch/papers/android-natt-keepalive-vpn-bypass
exceptione 3 hours ago
> A proper fix would require changes in the Android system. The researcher who discovered the leak has reported the issue to the Android Vulnerability Reward Program, but according to the researcher the issue was closed without action. This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.
If the account given by the researcher is correct, we cannot rule out that Google deliberately introduced or wanted to keep the leak in place.gib444 12 minutes ago
I guess the best advice remains to only use wifi to connect to a router which forces traffic over a VPN and never use mobile data?
replyDo any similar leaks exists on iOS currently?
aucisson_masque 5 hours ago
> This issue is not public, but based on this information we deem it unlikely that Google will do anything about it. GrapheneOS is aware of the issue and are working on a fix.
replyGood guy Google, as usual.