ImportantSecurity & Privacy
GrapheneOS fixes Android VPN leak Google refused to patch
A critical Android VPN bypass vulnerability that leaks users' real IP addresses even with VPN protections enabled was left unfixed by Google but patched by GrapheneOS within a week, highlighting a significant security gap in stock Android that affects enterprise mobile security posture. Google's refusal to classify the flaw as a security bulletin means millions of Android users remain vulnerable to IP address leakage through a simple API exploitation requiring only standard permissions. IT leaders must evaluate their organization's mobile security strategy, particularly around BYOD policies and VPN enforcement, while considering hardened alternatives like GrapheneOS for high-risk users or confidential work.
Hacker News3 min read

A critical Android VPN bypass vulnerability that leaks users' real IP addresses even with VPN protections enabled was left unfixed by Google but patched by GrapheneOS within a week, highlighting a significant security gap in stock Android that affects enterprise mobile security posture. Google's refusal to classify the flaw as a security bulletin means millions of Android users remain vulnerable to IP address leakage through a simple API exploitation requiring only standard permissions. IT leaders must evaluate their organization's mobile security strategy, particularly around BYOD policies and VPN enforcement, while considering hardened alternatives like GrapheneOS for high-risk users or confidential work.