Novel attack against virtually all VPN apps neuters their entire purpose

Open link in next tab

Novel attack against virtually all VPN apps neuters their entire purpose

https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/

TunnelVision vulnerability has existed since 2002 and may already be known to attackers.

Novel attack against virtually all VPN apps neuters their entire purpose

cross-posted from: https://beehaw.org/post/13643895

Pulling this off requires high privileges in the network, so if this is done by intruder you're probably having a Really Bad Day anyway, but might be good to know if you're connecting to untrusted networks (public wifi etc). For now, if you need to be sure, either tether to Android - since the Android stack doesn't implement DHCP option 121 or run VPN in VM that isn't bridged.