Get the latest tech news

DNS traffic can leak outside the VPN tunnel on Android


We were recently made aware of multiple potential DNS leaks on Android. They stem from bugs in Android itself, and only affect certain apps.

We can potentially minimize the amount of times a tunnel re-configuration happens, but we currently don’t think this leak can be fully prevented. These finding also shows once again that “Block connections without VPN” does not live up to its name (or documentation) and that it has multiple flaws. Depending on your threat model this might mean that you should avoid using Android altogether for anything sensitive, or employ other mitigations to prevent the leaks.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of Android

Android

Photo of DNS

DNS

Photo of VPN tunnel

VPN tunnel

Related news:

News photo

Bitwarden launches new MFA Authenticator app for iOS, Android

News photo

More than two dozen Android vulnerabilities fixed … slowly

News photo

When is Google I/O 2024 and what to expect: Android 15, Gemini, Wear OS, and more