An Android VPN leak and the end of Mullvad's public encrypted DNS

A flaw lets any Android app send traffic around a VPN and reveal the real IP, even with "Block connections without VPN" on. Mullvad is also shutting down its public encrypted DNS on 2 November, so anyone who set it up by hand needs to switch.

Mullvad published two notices in September, one affecting anyone using a VPN on Android and the other anyone who set up Mullvad's public encrypted DNS by hand. A newly disclosed Android flaw lets any app, with no special permission, send some traffic outside the VPN even when "Block connections without VPN" is on. The researcher estimates that most devices on Android 12 and newer are affected, although not every model has been tested.

The flaw lies in keep-alive packets, small packets sent at intervals to hold a connection open. An app asks Android for a keep-alive UDP connection, which Android hands to the Wi-Fi or cellular chip to send. CyberInsider, a security news site, reports that the packets cannot carry arbitrary data but still reveal the device's real IP to the attacker's server.

The researcher reported the flaw to Google's Android Vulnerability Reward Program on 15 May, and Google later marked it as a duplicate. No fix or CVE (a public vulnerability identifier) had been communicated before disclosure, and Mullvad's announcement says Google is unlikely to act.

Mullvad's public encrypted DNS shuts down on 2 November. Its 3 September notice says running a privacy-focused public DNS is highly specialised work, so Mullvad will fund the Quad9 Foundation, a Swiss non-profit, instead. Mullvad VPN users are unaffected, because their queries go to the resolver on the VPN server.

Perspective

With "Block connections without VPN" on, the operating system checks that each connection goes through the tunnel, but keep-alive packets handed to the network chip never pass that check. CyberInsider's 11 September report found no reliable app-level fix. The hardware holds only a limited number of keep-alive connections, so in theory an app could fill every slot first. Mullvad's 10 September notice said it would not do this, since those connections would also leave outside the tunnel and a malicious app may already be leaking before the Mullvad app starts.

Mullvad's advice is to install only apps you trust and, if possible, use a security- and privacy-focused Android fork such as GrapheneOS. GrapheneOS officially supports only Pixel devices from the Pixel 6 onward. It merged a change disabling unprivileged hardware keep-alives on 28 September, and as of 29 September no release included it.

For people whose real IP must not leak, CyberInsider mentions putting the phone behind a router that enforces the VPN, provided cellular and other network paths are off. The protection ends when the phone leaves that network.

As of 29 September, GreatFire, which tests what the Great Firewall blocks, had recorded all 17 of its 90-day tests of mullvad.net as blocked. The blocked addresses include the download links for Mullvad's apps. Its two most recent conclusive tests of Quad9's DoH (DNS over HTTPS) address both showed interference, the latest on 3 September, so the DNS switch below matters mostly outside mainland China.

Quad9's privacy policy says users' IP addresses stay in memory only for the microseconds to milliseconds needed to answer a query. The same policy says Quad9 keeps aggregate counters by region, carrier network and protocol, without individual IPs. Switching still leaves every DNS query with a single operator.

Mullvad Browser users on default settings move to Quad9 automatically, while those who chose another Mullvad DNS variant should switch back to the default. Anyone else who set it up by hand should switch before 2 November. Mullvad's iOS and macOS profiles will stop working. Quad9's replacements for iPhone (iOS 14 or later) and Mac (Big Sur or later) are downloaded in Safari and expire on 19 January 2027.

On Android 9 or later, enter the hostname dns.quad9.net under Private DNS. That setting uses DNS over TLS, so the DoH address https://dns.quad9.net/dns-query does not belong there. With another VPN on, Quad9's guides say profiles and Private DNS are generally not used, and Quad9's addresses go in the VPN app's custom DNS setting. The guides are not available in Chinese.

Get new stories by RSS, newsletter or Bluesky