Android's NAT-T keepalive mechanism can leak traffic outside VPN protection, circumventing VPN lockdown features. The vulnerability affects users relying on always-on VPN for security.
Security researchers at Mullvad discovered that Android's NAT Traversal (NAT-T) keepalive offload feature bypasses VPN lockdown by routing traffic directly through the device's default network interface.
The keepalive mechanism, designed to maintain IPsec connections through network address translation, operates independently of VPN controls. This allows data packets to leak outside encrypted tunnels even when always-on VPN is enabled.
The issue stems from Android's network architecture, where keepalive traffic is processed at the hardware level before VPN filtering can intercept it. Users who depend on VPN lockdown to prevent any unencrypted traffic exposure face an unexpected gap in protection.
Affected users should verify their VPN provider's handling of keepalive traffic and consider disabling hardware offload if available. The discovery highlights ongoing challenges in Android's security model and the complexity of implementing foolproof VPN enforcement at the OS level.
LG pushed back against allegations from security researchers who claimed the company's smart TVs log and upload user data. The manufacturer says recent media coverage has created misconceptions about how its televisions operate.
The Dutch National Cyber Security Centre (NCSC) has issued a critical warning about two severe vulnerabilities in Check Point VPN software. Exploitation of the flaws is expected to begin imminently.
Fintech platform Revolut disclosed a customer data breach resulting from fraudulent government information requests. The company has notified affected customers and reported the incident to relevant authorities and financial regulators.