GrapheneOS fixes an Android VPN bypass that Google decided to leave alone


  • Android 16 flaw can allow regular apps to leak traffic outside of an active VPN
  • Google’s Android security team refused to fix the bug
  • GrapheneOS delivered an update that disables the underlying functionality

GrapheneOS, the privacy-focused alternative Android distribution, just patched a recently discovered Android VPN flaw that Google decided to leave alone.

A security researcher revealed the bug last week, showing that even the best VPN apps can be compromised by the operating system inside them in certain extreme circumstances. The flaw, dubbed “Tiny UDP Cannon,” affects Android 16 and can allow a regular app to leak data outside of an active VPN tunnel.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top