
AI Summary
A newly documented Android behavior allows traffic to bypass VPN tunnels during network switches, creating potential privacy risks for users relying on consistent encrypted routing.
- •Mullvad reports that Android can bypass VPN tunnels for specific traffic during network transitions.
- •The vulnerability occurs when the operating system prioritizes a new network connection over an existing VPN interface.
- •The exact conditions required to trigger this leak across various Android OEM skins remain partially undefined.
- •A definitive fix is not currently available, leaving security-conscious users to monitor connection stability.
Mullvad security researchers have identified a mechanism where Android devices may inadvertently route traffic outside of a VPN tunnel during network switches. This follows a long history of VPN-related leaks on the platform, where OS-level routing priorities often override application-level tunnel configurations. While the behavior is technically a design feature intended to maintain connectivity, it introduces friction for users who assume total traffic containment. Whether Google will implement a system-level 'always-on' enforcement that mitigates this specific transition gap remains the critical next step.
Sources
Topics
Get the story before everyone else.
1-minute briefings. Zero noise. Straight to your inbox.
Join our growing community of readers
Discussion
No comments yet. Be the first to start the conversation!