A newly discovered Android vulnerability allows malicious apps to leak traffic outside VPN tunnels by exploiting keep-alive UDP connections offloaded to hardware chips, exposing users' real IP addresses even when VPN blocking is enabled. The issue was reported to Google's vulnerability program but reportedly closed without action, though GrapheneOS is working on a fix.