A newly discovered Android vulnerability allows malicious apps to leak traffic outside VPN tunnels by exploiting keep-alive UDP connections offloaded to hardware chips, exposing users' real IP addresses even when VPN blocking is enabled. The issue was reported to Google's vulnerability program but reportedly closed without action, though GrapheneOS is working on a fix.
GrapheneOS released version 13 of its Messages app, completely rewriting the interface with Jetpack Compose and Material 3 design. The update includes two-pane layouts for large screens, enhanced conversation controls like pinning and snoozing, improved privacy features with opt-in link previews, and numerous crash fixes and security improvements across attachments, sharing, and message handling.