Is Android quietly undermining your VPN service?

Data leak
(Image credit: Shutterstock/dalebor)

It has been discovered that Android devices are designed to leak some user data when connecting to a new Wi-Fi network, and even the best VPN services cannot stop it. 

Mullvad VPN identified the quirk during a recent security audit, reporting that data leakage also occurs when the "Block connections without VPN (or VPN lockdown)" and/or "Always-on VPN" options are enabled. 

The data exposed during the connectivity check includes people's real IP address, DNS lookups, HTTPS and NTP traffic.

However, the leak does not appear to be a malfunction. In response to questions from the provider, Google explained that both of the features work as intended. 

Android features deceiving VPN users 

A VPN is a tool that people use, among other things, to encrypt internet traffic while hiding their real IP location. This allows access to censored sites, avoids bandwidth throttling and secures online anonymity - the latter point being especially important on public Wi-Fi connections. 

However, certain wireless networks (like hotel or public transport Wi-Fi, for example) might require a connectivity check before establishing the connection. And it's exactly on these occasions that Android VPN services leak some traffic details, whether or not the option to block unprotected connections has been activated. 

"We understand why the Android system wants to send this traffic by default," wrote  Mullvad VPN in a blog post. "However, this can be a privacy concern for some users with certain threat models."

Following Mullvad's request for an additional option to disable these connectivity checks when the "VPN lockdown" is on, Google developers explained that the leak is actually a design choice.

Specifically, the company claims that some VPN apps rely on these checks to properly function. The developers also said there are other exemptions that might be more risky, like those applied to some privileged applications. They also believe that the impact on users' privacy is minimal.

After taking into consideration the points raised by Google, Mullvad still thinks that its suggested additional feature could be beneficial for users. Most importantly, the provider is calling the big tech giant to at least be more transparent about its features.

"Even if you are fine with some traffic going outside the VPN tunnel, we think the name of the setting ('Block connections without VPN') and Android’s documentation around it is misleading. The impression a user gets is that no traffic will leave the phone except through the VPN."  

What's at stake for Android users?

According to Google, the privacy risks are basically non-existent for most people. However, Mullvad argues that the metadata exposed could be enough for experienced hackers to de-anonymize this information and track down users. 

"The connection check traffic can be observed and analyzed by the party controlling the connectivity check server and any entity observing the network traffic," explained the secure VPN provider. 

"Even if the content of the message does not reveal anything more than 'some Android device connected,' the metadata (which includes the source IP) can be used to derive further information, especially if combined with data such as Wi-Fi access point locations."

This might not be relevant for everyday users, but it could negatively affect those for whom privacy is paramount. After all, it's likely they have turned on the VPN lockdown feature exactly for this reason. 

TechRadar Pro has contacted Google for further information, but did not receive an immediate response.

TOPICS
Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
malware
Google warns of legit VPN apps being used to infect devices with malware
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Mullvad VPN working on a laptop
VPN firm warns against encryption backdoor in new ad
Vector illustration of the word Censored in a glitch distorted style
Google, Apple, and internet restriction – how Big Tech is making censorship "much worse" according to experts
Polygonal vector illustration of the virtual private network's shield reading VPN and world map on the background
The cost of a ‘free’ VPN: When cheap is expensive
Laptop with binary computer code and India flag on the screen
VPNs are disappearing from India's app stores – and a 2022 law may be the culprit
Latest in VPN
Demonstrators protesting against the arrest of the Mayor of Istanbul Ekrem Imamoglu block Atatürk Boulevard on March 22, 2025 in Ankara, Türkiye.
Turkey's social media ban has been lifted, but VPN usage is still high
Shape of Russia filled with Russian flag-colored internet codes on a black hacking background
A new wave of blocks in Russia targets VPN apps and Cloudflare subnets
A hand holds a smartphone displaying the NordVPN logo
NordVPN Prime hits lowest-ever price in VPN Spring sale
Digital hand set location on map with two pins. AI technology in GPs, innovation delivery, map location, future transport logistic, route path concept. GPs point. New office location, change address
What does your IP address reveal about you?
ExpressVPN mobile app and Aircove
ExpressVPN ‘reduces workforce’ for the second time in two years
A stethoscope next to a laptop on a pink background
How to check if your VPN is working
Latest in News
Open AI
OpenAI live stream - could we see a major ChatGPT upgrade?
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
NetSuite EVP Evan Goldberg at SuiteConnect London 2025
"It's our job to deliver constant innovation” - NetSuite head on why it wants to be the operating system for your whole business
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection