Tag: Mullvad VPN

Critical Mullvad VPN Vulnerabilities Let Attackers Execute Malicious Code
News

Critical Mullvad VPN Vulnerabilities Let Attackers Execute Malicious Code

The well-known Mullvad VPN service has a number of high-severity flaws that security researchers have found that might let hackers run malicious code and jeopardize user privacy. The vulnerabilities were found in late 2024 when X41 D-Sec GmbH carried out a thorough security audit. The most significant problems in Mullvad's signal handler code are related to race circumstances and temporal safety violations, which may cause memory corruption and possibly even code execution. Researchers caution that an attacker who can set off a signal at the proper time might be able to take advantage of these vulnerabilities, even if exploitation is thought to be difficult. Exploitation is possible if an attacker can set off a signal in the correct situation because the alternate stack collides wit...
Android bug leaks DNS queries even when VPN kill switch is enabled
News

Android bug leaks DNS queries even when VPN kill switch is enabled

A Mullvad VPN user has found that even when the "Always-on VPN" feature is selected with the "Block connections without VPN" option, Android devices leak DNS queries when switching VPN servers. "Always-on VPN" is intended to launch the VPN service at boot time and maintain it active for the duration that the device or profile is powered on. By turning on the "Block Connections Without VPN" option, commonly referred to as a "kill switch," users can prevent prying eyes from tracking their online activities by making sure that ALL network traffic and connections go through the constantly connected VPN tunnel. But even with these features activated on the most recent OS version (Android 14), Mullvad discovered during his investigation into the problem reported on April 22 that an And...