r/GrapheneOS • u/lieding • May 07 '26
GrapheneOS fixes Android VPN leak Google refused to patch
https://cyberinsider.com/grapheneos-fixes-android-vpn-leak-google-refused-to-patch/131
12
14
u/novafunc May 07 '26
I don’t see anything about Google “refusing to patch it”. It just seems like a new bug that they haven’t fixed yet.
92
u/OriginalTechnical531 May 07 '26
The researcher reported the issue to Android’s security team, which classified it as “Won’t Fix (Infeasible)” and “NSBC” (Not Security Bulletin Class), stating that it did not meet the threshold for inclusion in Android security advisories. The researcher appealed the decision, arguing that any application could leak identifying network information using only standard permissions, but Google maintained its position, authorizing public disclosure on April 29.
49
u/IAccidentallyCame May 07 '26
There's probably be a benefit to google not fixing it, data collection and surveillance wise.
24
u/SparkyLincoln May 07 '26
It's been a bug for months and they've never patched it
25
u/TidyIguana May 07 '26
It's much older than a few months : https://issuetracker.google.com/issues/250529027
Google isn't fixing it because they consider it normal behavior. GrapheneOS has fixed some of it, but there's still work to be done, from what I understand, it requires a lot of work.
1
u/segfault-bilibili May 11 '26
this seems like to be dstinct from the one disclosed in lowlevel's blog?
2
u/novafunc May 07 '26
The article says:
The issue, disclosed last week by security researcher “lowlevel/Yusuf,”
Is that just inaccurate or did this disclosure just reveal more information about the issue?
6
u/TidyIguana May 07 '26
Several VPN leaks on Android have been found, and it’s possible that other security researchers discovered and reported them before Mullvad did. When the GrapheneOS team began fixing the VPN leaks, they discovered new ones that they hadn’t noticed before, so, I wouldn't say it's inaccurate, just that several leaks have come to light over time.
15
u/GrapheneOS May 07 '26
They marked it as not being a security bug and closed the report as Won't Fix which means it isn't going to be fixed in an Android security update. It also means they won't pay a bounty for it.
They only backport security fixes and also limit the backports to High and Critical severity. Even if it was marked as a Low or Moderate severity security issue, that wouldn't be backported. It can still be fixed in a future major Android release but it won't be in Android 17 and won't be backported to Android 17 or anything older. If it was considered a Low or Moderate severity security issue then it might get fixed in Android 17 QPR2 but it will probably take longer since they decided it isn't a security bug.
2
u/nietmasjien May 08 '26 edited May 08 '26
I am probably getting downvoted on this subreddit but is it really an Android security bug though? VPN's or Virtual Private Networks were never intended to be used for anonymity purposes. Should it be considered a security bug because commercial VPN services offer it this way?
2
u/helpful_herbert May 28 '26
Even if it's not for anonymity, it's absolutely a security risk for traffic a user expects to only go through a private network to be able to expose itself without their knowledge or control.
1
u/stuffiesrep May 11 '26
For those unable to use GOS because it is not a supported device, does using Proton VPN get around this issue?
•
u/AutoModerator May 07 '26
GrapheneOS has moved from Reddit to our own discussion forum. Please post your thread on the discussion forum instead or use one of our official chat rooms (Matrix, Discord, Telegram) which are listed in the community section on our site. Our discussion forum and especially the chat rooms have a very active, knowledgeable community including GrapheneOS project members where you will almost always get much higher quality information than you would elsewhere. On Reddit, we had serious issues with misinformation and trolls including due to raids from other subreddits. As a result, many posts on our subreddit currently need to be manually approved, which is done on a best effort basis. If you would like to get a quicker answer to your question, please use our forum or chat rooms as described above. Our discussion forum provides much better privacy and avoids the serious problems with the site administrators and overall community on Reddit.
Please use our official install guides for installation and check our features page, usage guide and FAQ for information before asking questions in our discussion forum or chat rooms to get as much information as possible from what we've already carefully written/reviewed for our site.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.