
An Android app can leak the device's real IP and roughly a kilobyte of arbitrary data outside an active VPN tunnel. CVE-2026-45182 abuses registerQuicConnectionClosePayload on the ConnectivityManager system service. An app registers a byte buffer and a UDP socket. When the socket closes, system_server sends the payload. Running as system UID, system_server is exempt from VPN routing - no VPN-aware check enforces tunneled egress, so the data exits on the physical Wi-Fi or cellular interface. Works even with Always-On VPN and Block connections without VPN enabled. Affected: Android 16 QPR1 and later, from tag android-16.0.0_r3. Discovered by @cybaqkebm. Writeup: "The Tiny UDP Cannon: An Android VPN Bypass" at http://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass. Reported to Android VRP on April 12. Closed "Won't Fix (Infeasible)" and "Not Security Bulletin Class" on April 18. Appeal citing CVE-2023-21383 denied April 24. GrapheneOS shipped a patch in their May 4 release. Mitigation on stock Android requires adb: adb shell device_config put tethering close_quic_connection -1 adb reboot The setting persists across reboots but may need reapplying after a system update. A system service built for graceful QUIC teardowns becomes the leak path.
Post summary
CVE-2026-45182 exposes a VPN bypass via QUIC tear‑down, with a publicly available PoC writeup and mitigation steps, but no evidence of active exploitation.
