CVE-2026-45182 Details
Description
GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let system_server transmit UDP traffic on its behalf. This occurs when the "Block connections without VPN" and "Always-on VPN" settings are enabled.
A vulnerability in GrapheneOS prior to release 2026050400 allows applications to leak the real IP address of a VPN user. This issue arises from a QUIC connection optimization that lets apps send UDP traffic through the system's server process, bypassing VPN protections. The vulnerability is present when the 'Block connections without VPN' and 'Always-on VPN' settings are enabled.
Users can update to GrapheneOS release 2026050400, which disables the problematic QUIC connection optimization and includes the May 2026 Android security patch. Instructions for updating are available on the GrapheneOS website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass/ | CISA-ADP | ExploitTechnical Analysis |
| https://cyberinsider.com/grapheneos-fixes-android-vpn-leak-google-refused-to-patch/ | [email protected] | AdvisoryRemedy |
| https://grapheneos.org/releases#2026050400 | [email protected] | Release NotesVendor |
| https://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass/ | [email protected] | ExploitTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| GrapheneOS | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | CVE Modified | CISA-ADP |
| May 9, 2026 | New CVE Received | [email protected] |
Volerion