Android NAT-T keepalive offload bypasses VPN lockdown
This research shows that Android’s Always-on VPN and "block connections without VPN" setting can be bypassed by a public NAT-T keepalive offload path, allowing certain Android apps to generate traffic that leaves the device outside the VPN tunnel on most Android 12+ devices. For CIOs and technology leaders, the business risk is a potential data-exposure and compliance gap in mobile fleets: a control that is often assumed to provide fail-closed protection may not fully contain device identity or network activity, weakening zero-trust and remote-access strategies. IT organizations should treat this as a platform-level exposure, not just a VPN client issue, and reassess Android device policy, app risk, and vendor mitigation plans across managed fleets.
