GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN" settings are enabled.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 10 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android VPN IP Leakage via System Server UDP Path |
Sat, 09 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN" settings are enabled. | |
| Weaknesses | CWE-441 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-09T22:12:55.615Z
Reserved: 2026-05-09T22:07:58.636Z
Link: CVE-2026-45182
No data.
Status : Received
Published: 2026-05-09T23:16:32.277
Modified: 2026-05-09T23:16:32.277
Link: CVE-2026-45182
No data.
OpenCVE Enrichment
Updated: 2026-05-10T00:30:05Z
Weaknesses