‘Won’t Fix’—All VPN Apps Affected As Google Android 16 Leaks Info

‘Won’t Fix’—All VPN Apps Affected As Google Android 16 Leaks Info

‘Won’t Fix’—All VPN Apps Affected As Google Android 16 Leaks Info

https://www.forbes.com/sites/daveywinder/2026/05/14/wont-fix-all-vpn-apps-affected-as-google-android-16-leaks-info/

Publish Date: 2026-05-14 09:33:00

Source Domain: www.forbes.com

Google Android 16 bug leaks info from all VPN apps.

SOPA Images/LightRocket via Getty Images

A security researcher has published a technical paper detailing how Android 16 has introduced a bug that essentially bypasses VPN protections, affecting all VPN apps. Whether you have enabled the “Always-On VPN” or “Block connections without VPN” settings is immaterial; Android 16 can still leak traffic outside of the VPN protected tunnel. This means that your real IP address is visible on the internet, with all the potential for tracking and surveillance issues that come with it. But here’s the kicker: the researcher reported the bug through the Android Vulnerability Reward Program only for Google to close the issue and mark it as “Won’t Fix” for falling outside of the threat model. I approached Google for a statement on Wednesday, May 13, but at the time of publication, none was forthcoming.

ForbesGoogle Targets Caller ID Spoofing As Scam Losses Reach $980 Million AnnuallyBy Davey Winder

The Android 16 VPN Vulnerability Explained

My attention was drawn to the issue when Yusef, a security researcher based in Zurich who goes by the X handle of @cybaqkebm, posted a simple statement: “Turns out ‘Always-On VPN’ and ‘Block connections without VPN’ features on Android aren’t that reliable.” The link in the tweet led me to a highly technical report detailing an Android 16 VPN bypass. The gist of it is that the two settings mentioned, meant to be a hard guarantee that no information will leave your device outside of the established VPN tunnel, are nothing of the sort.

Given that Google has previously warned about the dangers of malicious VPNs and advised users to “only download VPN apps from official sources, and check for apps with the VPN badge in Google Play,” you might think that this would be something that it would take very seriously indeed. Yet, Yusef has confirmed, after reporting the vulnerability through the Android VRP, “apparently, it…

Source