GrapheneOS fixes an Android VPN bypass that Google decided not to


  • An Android 16 bug could let regular apps leak traffic outside of an active VPN
  • Google’s Android Security Team declined to fix the bug
  • GrapheneOS has released an update that disables the underlying feature

GrapheneOS, the privacy-focused alternative Android distribution, has just fixed a newly discovered Android VPN bug that Google decided to leave behind.

A security researcher revealed the flaw last week, showing that even the best VPN apps can be undermined by the operating system underneath it in some extreme circumstances. The flaw, nicknamed “Tiny UDP Cannon,” affects Android 16 and can allow a regular app to leak data outside an active VPN tunnel.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top