CVE-2023-21383PoC(google / android)

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google android systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Settings, there is a possible way for the user to unintentionally send extra data due to an unclear prompt. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

2.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
android

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-12: 1PoC Mentioned / Linked · 2026-05-12: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-12: 105-12
Signal classification1 categories
PoC
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • SecureChap@SecureChap
    PoC

    An Android app can leak the device's real IP and roughly a kilobyte of arbitrary data outside an active VPN tunnel. CVE-2026-45182 abuses registerQuicConnectionClosePayload on the ConnectivityManager system service. An app registers a byte buffer and a UDP socket. When the socket closes, system_server sends the payload. Running as system UID, system_server is exempt from VPN routing - no VPN-aware check enforces tunneled egress, so the data exits on the physical Wi-Fi or cellular interface. Works even with Always-On VPN and Block connections without VPN enabled. Affected: Android 16 QPR1 and later, from tag android-16.0.0_r3. Discovered by @cybaqkebm. Writeup: "The Tiny UDP Cannon: An Android VPN Bypass" at http://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass. Reported to Android VRP on April 12. Closed "Won't Fix (Infeasible)" and "Not Security Bulletin Class" on April 18. Appeal citing CVE-2023-21383 denied April 24. GrapheneOS shipped a patch in their May 4 release. Mitigation on stock Android requires adb: adb shell device_config put tethering close_quic_connection -1 adb reboot The setting persists across reboots but may need reapplying after a system update. A system service built for graceful QUIC teardowns becomes the leak path.

    Post summary

    CVE-2026-45182 exposes a VPN bypass via QUIC tear‑down, with a publicly available PoC writeup and mitigation steps, but no evidence of active exploitation.

    00000107
    153 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---

Explore more