Android 16 Bug Allows Apps to Ignore VPNs and Leak IP Addresses

TL;DR AI
2 min readKey summary
A researcher says Android 16’s ConnectivityManager can send connection-end messages outside the VPN tunnel, exposing a device’s real IP address.
The issue could bypass VPN protection even with always-on VPN enabled, undermining a key privacy safeguard.
Google reportedly closed the report as infeasible to fix, while Mullvad publicized the finding and GrapheneOS issued a patch.
If confirmed, the flaw could mislead users who rely on VPNs for anonymity or traffic protection.



