logo

‘TunnelVision’ Attack Leaves Nearly All VPNs Vulnerable to Spying

ID: db22fd69-b427-56db-95f2-d698c7ee3654

STIX ID: report--db22fd69-b427-56db-95f2-d698c7ee3654

Feed Name: WIRED Security

Threat Score
70/100

Date Published: 2024-05-10

Date Updated: 2026-04-26

Author: Dan Goodin, Ars Technica

...
...

Leviathan Security researchers describe “TunnelVision”, a technique that abuses DHCP option 121 to push specific routes to a VPN client’s routing table so that VPN-protected traffic is diverted through a malicious DHCP gateway and transmitted unencrypted; Android is immune but most other OSes lack complete fixes. The report includes PoC behavior, attacker requirements (network administrative control or a rogue DHCP on the local LAN), limited mitigations (VMs with non-bridged adapters, mobile hotspots, firewall rules), and the privacy and de-anonymization risks posed by the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.