Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address
ID: 30584582-175c-5db9-a8ab-60e67e2246e5
STIX ID: report--30584582-175c-5db9-a8ab-60e67e2246e5
Feed Name: cybersecurityNews.com
Threat Score
A design flaw in Android 16's ConnectivityManager (registerQuicConnectionClosePayload) allows regular apps with basic permissions to register payloads that system_server may send over the device's physical network interface, bypassing Always‑On VPN and VPN lockdown, leaking the real IP and enabling data exfiltration; researchers demonstrated the issue on a Pixel 8, published IOCs and a temporary ADB mitigation, and reported it to Google's VRP, which declined to fix it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
