Google sure seems to not care about VPN leak bugs that easily enable user apps to track real-world IP addresses without any kind of special permissions, even while the user thinks they're safe in 'lock traffic to VPN only mode'.
I wonder why..
Via Graphene issue tracker.
Author: ArminShupuk
@thestinger As I see that you, Daniel, have picked this one up, I want to add that I was just in touch with Yusuf, who found the registerQuicConnectionClosePayload VPN leak. He informed me today that they didn't pay him and closed the report as "won't fix." He had no success with his appeal. Mine seems to be "won't fix" too, with no success reasoning with them either.
So there are currently already two arbitrary ways for any user app with internet permission to leak the IP address in VPN lockdown mode that won't be fixed upstream.
Side note, the main GrapheneOS dev being his usual abrasive self (this is his only contribution to the thread).
Author: thestinger
That's not the spelling of my name.