The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.

GOS fix in progress. Google has reportedly declined the bug report/bounty.

    • notSys@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      24 days ago

      Fdroid can be a security hole. They might not awarded security bounty for some reason. Those 2 things are not connected

      • one_old_coder@piefed.social
        link
        fedilink
        English
        arrow-up
        2
        ·
        24 days ago

        Hypocrisy is the connection.

        F-droid shows the permissions used. Google has a huge hole, on purpose, that bypasses VPNs.