The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.

GOS fix in progress. Google has reportedly declined the bug report/bounty.

  • one_old_coder@piefed.social
    link
    fedilink
    English
    arrow-up
    39
    arrow-down
    2
    ·
    9 days ago

    Google has reportedly declined the bug report

    Yet another proof that preventing stores like F-droid is a good security choice /s

        • notSys@lemmy.cafe
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          5 days ago

          Fdroid can be a security hole. They might not awarded security bounty for some reason. Those 2 things are not connected

          • one_old_coder@piefed.social
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 days ago

            Hypocrisy is the connection.

            F-droid shows the permissions used. Google has a huge hole, on purpose, that bypasses VPNs.

    • CosmicTurtle0 [he/him]@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      16
      ·
      9 days ago

      In other words, Google prefers security researchers to immediately share vulnerability findings publicly immediately. That way users can properly mitigate their risks appropriately while Google decides whether fixing the vulnerability will affect their bottom line.