logo

Android 16 VPN Bypass Lets Malicious Apps Reveal Users Real IP Address

ID: 30584582-175c-5db9-a8ab-60e67e2246e5

STIX ID: report--30584582-175c-5db9-a8ab-60e67e2246e5

Feed Name: cybersecurityNews.com

Threat Score
68/100

Date Published: 2026-05-16

Date Updated: 2026-05-16

Author: Abinaya

...
...

A design flaw in Android 16's ConnectivityManager (registerQuicConnectionClosePayload) allows regular apps with basic permissions to register payloads that system_server may send over the device's physical network interface, bypassing Always‑On VPN and VPN lockdown, leaking the real IP and enabling data exfiltration; researchers demonstrated the issue on a Pixel 8, published IOCs and a temporary ADB mitigation, and reported it to Google's VRP, which declined to fix it.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.