Android 16 VPN Bypass Lets Apps Reveal Users’ Real IP Address
ID: 72886156-3f10-5693-979c-f288490415c3
STIX ID: report--72886156-3f10-5693-979c-f288490415c3
Feed Name: Cyber Press
Threat Score
A critical Android 16 vulnerability in the new registerQuicConnectionClosePayload API lets any app with INTERNET and ACCESS_NETWORK_STATE cause system_server to send attacker-controlled QUIC teardown payloads over the device's physical interface, leaking the real public IP even when Always-On VPN with lockdown is enabled. Confirmed on a Pixel 8 with Proton VPN; Google has not patched and a temporary ADB workaround is provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
