Android 16 mit IP-Leaks selbst bei aktiver VPN-App

Vorsicht vor IP-Leaks! Jede App auf aktuellen Android-Versionen kann Datenverkehr nach außen leiten und so die eigene IP-Adresse verraten.

TARNKAPPE.INFO

Leaking IPs in Brave Tor Window & Chrome VPNs via Popunders & CSP Bypass

Bug bounty writeup on IP leaks in Brave Tor window and Chrome VPN extensions via BackgroundFetch/WebAuthn and popunder/CSP bypasses.

https://0x999.net/blog/leaking-ips-in-brave-tor-window-chrome-vpns-popunders-csp-bypass

#IPLeak #BrowserPrivacy

Leaking IPs in Brave Tor Window & Chrome VPNs + Popunders + CSP Bypass

This writeup details multiple IP leak vulnerabilities I discovered affecting Brave's Tor window and Chrome VPN extensions that allowed a malicious actor to leak the real IP address of any visitor to a remote host. Also covers a connect-src CSP bypass for DNS-based data exfiltration and two new Popunder techniques that work on Chrome, Firefox & Safari.