
Mullvad has warned about a newly documented Android flaw that allows ordinary apps to send traffic outside an active VPN tunnel, potentially exposing a user’s real IP address even when Android’s “Block connections without VPN” protection is enabled.
The issue was discovered by software engineer and entrepreneur Armin Šupuk, who published a detailed technical report in his blog. Mullvad highlighted the research this week, warning that exploitation does not require root access, special privileges, or dangerous Android permissions.
Šupuk found that an app can misuse Android’s NAT-T keepalive functionality, which is normally intended to maintain connections used for IPsec and network address translation. By requesting a hardware-offloaded keepalive, an app can cause the phone’s Wi-Fi hardware to periodically transmit UDP packets on port 4500 directly over the physical network.
Because those packets are generated below Android’s normal application networking path, they can bypass the controls responsible for forcing app traffic through the VPN.
A server controlled by the attacker can then observe the connection’s actual source IP address and packet timing. The technique does not allow arbitrary data to be smuggled outside the VPN, as Android controls the keepalive packet format, but it is sufficient to reveal the device’s non-VPN network identity.
Mullvad is a Sweden-based VPN provider focused heavily on user privacy, including minimizing account information and reducing exposure of identifying metadata. The company said the flaw requires changes in Android itself and does not currently plan to implement a proposed workaround involving deliberately exhausting the limited number of hardware keepalive slots.
Šupuk demonstrated the bypass on a Pixel 8 Pro running Android 16, where an external router capture observed UDP/4500 packets leaving the physical Wi-Fi connection every 10 seconds while Mullvad VPN and Android’s lockdown setting were active.
Additional testing showed that the underlying keepalive mechanism could also be activated on Samsung and Nothing devices running Android 16. Based on Android’s shared framework implementation and supported wireless hardware, Šupuk estimates that the affected device class includes most Android 12 and newer devices, although not every model has been individually tested.
The researcher reported the issue to Google’s Android Vulnerability Reward Program on May 15. According to his disclosure timeline, Google later marked the submission as a duplicate of an existing issue, while no fix or CVE had been communicated before public disclosure.
GrapheneOS, the privacy- and security-focused Android distribution, has acknowledged the problem and says it plans to fix it. One developer said the project had known about the flaw since publication and would address it, while noting that other VPN leak classes were receiving higher priority.
GrapheneOS previously disabled another Android networking feature in May after researcher Yusuf disclosed a separate mechanism that allowed apps to leak a device’s IP address outside VPN lockdown using QUIC connection-close packets.
For Android users, there is currently no reliable app-level fix for the newly disclosed NAT-T issue. Mullvad recommends limiting installations to trusted applications and, where appropriate, using a security-focused Android distribution such as GrapheneOS. Users facing unusually high privacy risks can also place the phone behind a VPN-enforcing router, provided cellular and other alternative network paths are disabled.
CyberInsider contacted Google for comment on the vulnerability but did not receive a response by publication time.







Leave a Reply