A normal Android app can send Wi-Fi keepalives outside VPN lockdown.
The destination sees the device's real source address and packet timing.
Affects
Android phones whose framework and Wi-Fi firmware expose unprivileged NAT-T keepalive offload, including a demonstrated Pixel 8 Pro running Android 16.
What it enables
VPN-lockdown bypass for real network-identity and activity-timing disclosure
Attacker induces the victim to run an ordinary app requiring no dangerous permissions.→↓The app opens a UDP encapsulation socket and requests a NAT-T socket keepalive through public Android APIs.→↓ConnectivityService passes the request to Wi-Fi offload without applying the caller UID's VPN-lockdown policy.→↓The Wi-Fi chipset emits fixed-format UDP/4500 keepalives on the physical interface rather than through the VPN.→↓The attacker-controlled endpoint observes the device's real source address and packet timing.→↓The full affected-device population is not established.
Research leadExternally capture keepalives on representative Samsung, Nothing, MediaTek and Qualcomm Android 12–16 devices with VPN lockdown enabled.
Why this matters
The change is a demonstrated escape from an explicit operating-system guarantee through public APIs available to an ordinary app.
Detail, proof-of-concept code and 4 sources
Required access
Execution of a normal third-party app on an affected Android device using Wi-Fi while Always-on VPN and Block connections without VPN are enabled.
Affected versions
Android 16 on Pixel 8 Pro, demonstrated by external packet capture, Android 12 and later implementations exposing app-visible NAT-T keepalive offload slots; broader scope remains provisional
With Always-on VPN and Block connections without VPN enabled, an app can request a NAT-T socket keepalive. Android passes it to Wi-Fi hardware offload without applying the caller UID's effective lockdown policy.
Researchers captured the resulting UDP/4500 traffic outside the tunnel on a Pixel 8 Pro. Samsung and Nothing devices exposed compatible active offload slots, but we do not yet know the full affected-device population.
Evidence
Research report demonstrates the API sequence and external packet capture on a Pixel 8 ProMullvad independently assessed the VPN-lockdown consequence and publicized the researchA shipped Android fix or fixed-version boundary was available by the cutoff
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.