No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 13 May 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 10 May 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grapheneos
Grapheneos grapheneos |
|
| Vendors & Products |
Grapheneos
Grapheneos grapheneos |
Sun, 10 May 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Android VPN IP Leakage via System Server UDP Path |
Sat, 09 May 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN" settings are enabled. | |
| Weaknesses | CWE-441 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-11T15:00:48.072Z
Reserved: 2026-05-09T22:07:58.636Z
Link: CVE-2026-45182
Updated: 2026-05-11T15:00:43.738Z
Status : Deferred
Published: 2026-05-09T23:16:32.277
Modified: 2026-05-13T15:46:19.993
Link: CVE-2026-45182
No data.
OpenCVE Enrichment
Updated: 2026-05-10T21:24:22Z