Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It
Six months after widespread reports of VPN server address leaks on Android, an independent analysis shows that only a handful of clients have addressed the issue, while many others either ignored reports or closed them without fixes.
The investigation identifies two separate leaks that are frequently confused. The first occurs when VPN clients expose a local SOCKS proxy on 127.0.0.1 without authentication. Any application can connect to this port and route traffic through the VPN tunnel, revealing the server address even if the app was explicitly excluded from the tunnel. The second leak is independent of proxies and stems from Android’s handling of SO_BINDTODEVICE on the tun interface.
How the tun0 Leak Works
When split tunneling excludes an application, Android removes the route to tun0 for that app’s UID. However, any process can still call setsockopt to bind a socket directly to tun0. The kernel then forwards packets through the interface anyway. The VPN client receives the packet, encrypts it, and sends it to the remote server, exposing the server IP to the destination. No root access or custom code is required; a simple curl command from Termux placed in the exclusion list reproduces the leak.
Testing showed that excluded applications, including the open-source RKNHardering detector, successfully reached the VPN server and recorded its address multiple times.
Client Responses
Most clients addressed only the local proxy issue in April by adding random ports and passwords. AmneziaVPN, TeapodStream and v2rayNG implemented this change, though v2rayNG leaves the protection disabled by default. Karing, Throne and FlClash followed similar approaches.
For the tun0 leak, only two projects implemented proper owner verification. TeapodStream rewrote its tun2socks layer to check every connection with ConnectivityManager.getConnectionOwnerUid. After notification, the developer released version 1.6.6 that correctly rejects packets returning INVALID_UID when exclusions are active. OlConnect performs a similar check but still accepts INVALID_UID in all modes and was unreachable for comment.
sing-box added a package_name_regex rule that can reject unknown owners, but users must insert it manually. AmneziaVPN received a series of pull requests covering both AmneziaWG and the full client stack; none have been merged yet. v2rayNG closed the tun0 report as “not planned.”
No public statements or fixes were found for WireGuard for Android, Mullvad, Proton VPN, IVPN, Cloudflare WARP, Outline, Tailscale, NordVPN, Windscribe, Lantern, Psiphon or OpenVPN for Android.
Users can verify their own client with one Termux command that attempts to reach ifconfig.me through the tun interface while the app is excluded from the VPN.
Related articles
Part 2: How Third-Party Developers Closed the tun0 Leak in AmneziaVPN on Android
Third-party contributors to AmneziaVPN have detailed their fix for a VPN tunnel bypass affecting excluded applications on Android. The vulnerability allows any app, even those disallowed from the VPN, to bind sockets directly to the tun0 interface using SO_BINDTODEVICE and thereby discover the VPN server address. The team implemented a packet filter inside the client that queries Android via ConnectivityManager.getConnectionOwnerUid to determine packet ownership and drops traffic from unknown UIDs. The solution was integrated into both the Xray and AmneziaWG traffic paths, with the AmneziaWG hook placed inside amneziawg-go after packet parsing. Testing with leak_probe.py showed zero successful bypass attempts out of six methods when the filter was active, compared to six out of six without it. The developers submitted three pull requests and released a side-loaded test build, while noting remaining limitations such as raw sockets and tethering scenarios.
Cisco Confirms Active Exploitation of CVE-2026-76504 in Catalyst SD-WAN Manager
Cisco has confirmed that the critical vulnerability CVE-2026-76504 in Catalyst SD-WAN Manager has been exploited in attacks throughout September. The flaw carries a CVSS score of 9.8 and allows attackers to gain full administrator access without any credentials by bypassing API authentication through malformed URI encoding. The issue affects the login session handling mechanism, enabling forged requests to grant netadmin privileges by default. Similar URI manipulation techniques were observed earlier this month in Oracle PeopleSoft attacks. Patches are available across multiple release trains including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, while older installations must migrate to supported versions. Cisco recommends restricting access to trusted hosts and placing the Manager behind firewalls until updates are applied. The vulnerability was discovered during routine support operations and verified by Cisco's Product Security Incident Response Team.
Zero-Days in PaperCut MF Chained to Compromise Active Directory in Education Sector
Analysts at eSentire investigated an attack that chained two zero-days in PaperCut MF, tracked as CVE-2026-81578 and CVE-2026-82078, to move from an internet-exposed print server to a domain controller in an education sector client in under two days. Attackers gained initial access through the card or badge query field, delivering malicious Java code that allowed unauthenticated configuration changes and arbitrary bytecode execution on version 24.0.2. The first stage loader reassembled payload fragments in memory, launched the next stage, and deleted its own files while remaining compatible with multiple Tomcat versions. A web shell followed, accepting commands via a custom HTTP header, reading configurations, and erasing log traces while positioning itself early in the request processing chain. The command-and-control implant was AdaptixC2, hidden inside a modified Microsoft Copilot binary downloaded from Alibaba Cloud infrastructure. Privilege escalation was achieved without passwords by locating a domain-privileged service account, stealing its access token, and relaunching the implant under those rights. On the domain controller the payload arrived via administrative share and was executed by modifying the Windows PlugPlay service, after which the legitimate path was restored to minimize traces. The operators extracted credentials from memory and registry, enabled Restricted Admin mode, used an NTLM hash for RDP access, and copied the full Active Directory database containing passwords for all domain accounts.
Apache WSS4J Library Addresses Seven Vulnerabilities Including Authentication Bypass Flaws
The Apache WSS4J library, used to apply WS-Security to SOAP messages in Java environments, has received updates fixing seven vulnerabilities. The development team disclosed multiple security advisories on September 30, 2026, covering the issues. Three vulnerabilities received an Important severity rating: CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616. CVE-2026-88920 allows authentication bypass in the DOM security processor by injecting attacker-controlled keys into crafted unsigned sender-vouches SAML assertions. CVE-2026-89238 stems from improper handling of encryption headers, enabling attackers to force plaintext elements to be treated as decrypted headers and bypass security policies. The remaining four vulnerabilities were also resolved in the same coordinated update release.