Part 2: How Third-Party Developers Closed the tun0 Leak in AmneziaVPN on Android
Third-party developers have published a detailed technical breakdown of how they closed a long-standing VPN tunnel leak affecting AmneziaVPN on Android. The issue, first reported in issue #2457, allows applications excluded from the VPN tunnel to bind sockets directly to the tun0 interface and thereby learn the address of the VPN server.
The root cause lies in Linux kernel behavior on versions 5.7 and newer. When an excluded application calls setsockopt(SO_BINDTODEVICE, "tun0"), the kernel falls back to treating the destination as an on-link neighbor if no matching routing rule exists for the UID. This bypasses the UID-based split-tunneling rules installed by VpnService and addDisallowedApplication.
The fix introduces a packet filter that inspects every outbound packet read from the tunnel descriptor. For each new flow the filter calls ConnectivityManager.getConnectionOwnerUid through a JNI bridge to obtain the UID. If the returned UID is INVALID_UID or belongs to the VPN client itself, the packet is dropped. In exclude mode this single rule effectively blocks all bypass attempts because excluded applications are never reported as owners.
The implementation was added to both traffic paths inside AmneziaVPN. On the Xray path the check sits inside the gVisor stack before SOCKS connections are created. On the AmneziaWG path a lightweight hook was placed inside amneziawg-go immediately after packet padding, maintaining a small cache of UID decisions to avoid repeated JNI calls.
Performance measurements on Android 16 showed no measurable increase in connection latency at 5000 new flows per second. When disabled, the filter adds only a single atomic read per packet and contributes no code to non-Android builds.
The authors stress that they are not official maintainers and that the three submitted pull requests remain unmerged. A side-loaded test build is available for verification. The article concludes with an extensive list of remaining edge cases, including raw sockets, IPv6, tethering, and certain UDP behaviors, together with a checklist for other VPN clients wishing to implement similar protections.
Related articles
Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It
A detailed investigation reveals that Android VPN clients suffer from two distinct server address leaks when split tunneling is enabled. The first leak, tied to an unprotected local SOCKS proxy on 127.0.0.1, was quickly mitigated by most Xray and sing-box based clients through random ports and passwords. The second, more persistent leak allows excluded applications to bind sockets directly to the tun0 interface and discover the VPN server IP without root or special permissions. Only TeapodStream and OlConnect implemented owner-UID checks using ConnectivityManager.getConnectionOwnerUid, yet both initially mishandled the INVALID_UID response returned for excluded apps. AmneziaVPN has unmerged pull requests that correctly reject unknown owners, while sing-box offers a manual package_name_regex rule. v2rayNG closed the report as not planned, and major clients including WireGuard for Android, Mullvad, Proton VPN and others have issued no statements.
Cisco Confirms Active Exploitation of CVE-2026-76504 in Catalyst SD-WAN Manager
Cisco has confirmed that the critical vulnerability CVE-2026-76504 in Catalyst SD-WAN Manager has been exploited in attacks throughout September. The flaw carries a CVSS score of 9.8 and allows attackers to gain full administrator access without any credentials by bypassing API authentication through malformed URI encoding. The issue affects the login session handling mechanism, enabling forged requests to grant netadmin privileges by default. Similar URI manipulation techniques were observed earlier this month in Oracle PeopleSoft attacks. Patches are available across multiple release trains including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, while older installations must migrate to supported versions. Cisco recommends restricting access to trusted hosts and placing the Manager behind firewalls until updates are applied. The vulnerability was discovered during routine support operations and verified by Cisco's Product Security Incident Response Team.
Zero-Days in PaperCut MF Chained to Compromise Active Directory in Education Sector
Analysts at eSentire investigated an attack that chained two zero-days in PaperCut MF, tracked as CVE-2026-81578 and CVE-2026-82078, to move from an internet-exposed print server to a domain controller in an education sector client in under two days. Attackers gained initial access through the card or badge query field, delivering malicious Java code that allowed unauthenticated configuration changes and arbitrary bytecode execution on version 24.0.2. The first stage loader reassembled payload fragments in memory, launched the next stage, and deleted its own files while remaining compatible with multiple Tomcat versions. A web shell followed, accepting commands via a custom HTTP header, reading configurations, and erasing log traces while positioning itself early in the request processing chain. The command-and-control implant was AdaptixC2, hidden inside a modified Microsoft Copilot binary downloaded from Alibaba Cloud infrastructure. Privilege escalation was achieved without passwords by locating a domain-privileged service account, stealing its access token, and relaunching the implant under those rights. On the domain controller the payload arrived via administrative share and was executed by modifying the Windows PlugPlay service, after which the legitimate path was restored to minimize traces. The operators extracted credentials from memory and registry, enabled Restricted Admin mode, used an NTLM hash for RDP access, and copied the full Active Directory database containing passwords for all domain accounts.
Apache WSS4J Library Addresses Seven Vulnerabilities Including Authentication Bypass Flaws
The Apache WSS4J library, used to apply WS-Security to SOAP messages in Java environments, has received updates fixing seven vulnerabilities. The development team disclosed multiple security advisories on September 30, 2026, covering the issues. Three vulnerabilities received an Important severity rating: CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616. CVE-2026-88920 allows authentication bypass in the DOM security processor by injecting attacker-controlled keys into crafted unsigned sender-vouches SAML assertions. CVE-2026-89238 stems from improper handling of encryption headers, enabling attackers to force plaintext elements to be treated as decrypted headers and bypass security policies. The remaining four vulnerabilities were also resolved in the same coordinated update release.