News

Mullvad warns of Android VPN leak that bypasses kill switch

Mullvad VPN AB's 10 September 2026 blog says a malicious Android app can leak the real IP over hardware-offloaded NAT-T UDP port 4500 even with Block connections without VPN on. Mullvad will not ship a keepalive-saturation workaround. GrapheneOS is working on a fix.

Mullvad warns of Android VPN leak that bypasses kill switch

Mullvad VPN AB, in a 10 September 2026 privacy blog, said a newly found leak in the Android network stack lets a malicious app send traffic outside the VPN tunnel even when "Block all connections without VPN" is on. That exposes the device's real IP.

This is a vendor privacy advisory from Mullvad. It is not a CVE assignment, not a Google security bulletin, and not a CISA Known Exploited Vulnerabilities listing. Mullvad says the path sits in Android itself, so it can hit any VPN that relies on that kill-switch toggle, not only Mullvad.

The app needs no special permission. The technique tells Android to create a NAT traversal keep-alive UDP connection offloaded to the Wi-Fi or cellular chip, then misuses that path to send UDP packets on port 4500 to any Internet server. Those packets leave from the network hardware, so they skip the check that all traffic must go through the VPN.

The researcher reported the issue to the Android Vulnerability Reward Program. Mullvad, citing that researcher, says the report was closed without action, the issue is not public, and Mullvad judges Google unlikely to act. CyberInsider (Alex Lekander, 11 September 2026), reading the researcher's timeline, says Google marked the submission as a duplicate. Either way, Mullvad's post does not name a public CVE id.

GrapheneOS is aware and working on a fix. Mullvad does not confirm a ship date.

A theoretical mitigation would saturate the limited hardware keep-alive slots so a later malicious app cannot open its own. Mullvad will not ship that workaround. It would still send packets outside the tunnel, and it can lose a race if malware starts first.

Mullvad's guidance is to install only trusted apps, and to prefer a privacy-focused Android fork such as GrapheneOS when that is possible.

Related tunnel and leak notes include Cloudflare 1.1.1.1 adding post-quantum DNSSEC, Check Point's critical VPN certificate flaws, ChatGPT's sandbox cross-account leak, and WeWorm's WeChat zero-click worm.

If you treat Android "Block all connections without VPN" as a kill switch, treat it as incomplete against hardware-offloaded NAT-T UDP on port 4500. Install only trusted apps, do not wait for a Mullvad keepalive workaround, and move to GrapheneOS if your threat model needs a system-level fix.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free