Skip to finding
§
High
Wi-Fi / Mobile
Provisional

A normal Android app can send Wi-Fi keepalives outside VPN lockdown.

The destination sees the device's real source address and packet timing.

Affects

Android phones whose framework and Wi-Fi firmware expose unprivileged NAT-T keepalive offload, including a demonstrated Pixel 8 Pro running Android 16.

What it enables

VPN-lockdown bypass for real network-identity and activity-timing disclosure

Attacker induces the victim to run an ordinary app requiring no dangerous permissions.→↓The app opens a UDP encapsulation socket and requests a NAT-T socket keepalive through public Android APIs.→↓ConnectivityService passes the request to Wi-Fi offload without applying the caller UID's VPN-lockdown policy.→↓The Wi-Fi chipset emits fixed-format UDP/4500 keepalives on the physical interface rather than through the VPN.→↓The attacker-controlled endpoint observes the device's real source address and packet timing.→↓The full affected-device population is not established.
Research leadExternally capture keepalives on representative Samsung, Nothing, MediaTek and Qualcomm Android 12–16 devices with VPN lockdown enabled.
Why this matters

The change is a demonstrated escape from an explicit operating-system guarantee through public APIs available to an ordinary app.

Detail, proof-of-concept code and 4 sources
Required access

Execution of a normal third-party app on an affected Android device using Wi-Fi while Always-on VPN and Block connections without VPN are enabled.

Affected versions

Android 16 on Pixel 8 Pro, demonstrated by external packet capture, Android 12 and later implementations exposing app-visible NAT-T keepalive offload slots; broader scope remains provisional

With Always-on VPN and Block connections without VPN enabled, an app can request a NAT-T socket keepalive. Android passes it to Wi-Fi hardware offload without applying the caller UID's effective lockdown policy.

Researchers captured the resulting UDP/4500 traffic outside the tunnel on a Pixel 8 Pro. Samsung and Nothing devices exposed compatible active offload slots, but we do not yet know the full affected-device population.

Evidence
Research report demonstrates the API sequence and external packet capture on a Pixel 8 ProMullvad independently assessed the VPN-lockdown consequence and publicized the researchA shipped Android fix or fixed-version boundary was available by the cutoff
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026