Android NAT-T Keepalive Offload Bypasses VPN Lockdown: Device-Class Exposure Across Most Android 12+ Devices
Summary
A technical report detailing an Android NAT-T keepalive offload bypass that leaks non-VPN traffic outside the VPN lockdown on Android 12+ devices. The study presents evidence from multiple OEMs, analyzes the root cause as a collapsed trust model, and proposes mitigations to restore fail-closed behavior for VPN lockdown. It highlights device-class exposure across most Android 12+ devices and calls for architectural and policy fixes to prevent future leaks.