- cross-posted to:
- tech@piefed.world
- cross-posted to:
- tech@piefed.world
The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.
GOS fix in progress. Google has reportedly declined the bug report/bounty.



Yet another proof that preventing stores like F-droid is a good security choice /s
What one has to do with another?
Google says F-droid is a security issue. Google refuses to fix their own security holes.
Fdroid can be a security hole. They might not awarded security bounty for some reason. Those 2 things are not connected
Hypocrisy is the connection.
F-droid shows the permissions used. Google has a huge hole, on purpose, that bypasses VPNs.
In other words, Google prefers security researchers to immediately share vulnerability findings publicly immediately. That way users can properly mitigate their risks appropriately while Google decides whether fixing the vulnerability will affect their bottom line.