The leak involves telling Android to create a keep-alive UDP connection that is offloaded to the hardware Wi-Fi or cellular chip.

GOS fix in progress. Google has reportedly declined the bug report/bounty.

you are viewing a single comment's thread
view the rest of the comments

In other words, Google prefers security researchers to immediately share vulnerability findings publicly immediately. That way users can properly mitigate their risks appropriately while Google decides whether fixing the vulnerability will affect their bottom line.

  • source
  • parent