Description
Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T02:51:11.410Z
Reserved: 2024-05-03T00:00:00.000Z
Link: CVE-2024-34446
Updated: 2024-08-02T02:51:11.410Z
Status : Awaiting Analysis
Published: 2024-05-03T15:15:08.210
Modified: 2024-11-21T09:18:41.320
Link: CVE-2024-34446
No data.
OpenCVE Enrichment
No data.
Weaknesses