PatchSiren cyber security CVE debrief
CVE-2026-45182 GrapheneOS CVE debrief
CVE-2026-45182 is a privacy leak in GrapheneOS before build 2026050400. Under the conditions described in the record, an application could cause system_server to transmit UDP traffic on its behalf, which could let an attacker discover the VPN user’s real IP address. The issue is associated with the "Block connections without VPN" and "Always-on VPN" settings being enabled. The published CVSS score is 2.2 (LOW), and the impact is limited to confidentiality.
- Vendor
- GrapheneOS
- Product
- GrapheneOS
- CVSS
- LOW 2.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-24
Who should care
GrapheneOS users who rely on Always-on VPN and Block connections without VPN, especially anyone who assumes all app traffic is fully forced through the VPN. Security teams supporting such devices should verify that affected builds are updated.
Technical summary
The NVD record and cited references describe a flaw tied to a registerQuicConnectionClosePayload optimization in GrapheneOS. In the affected configuration, an application could leverage system_server to send UDP traffic, creating a path that may disclose the device’s real IP address despite VPN enforcement settings. The CVSS vector provided by NVD is AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N, indicating local, high-complexity, user-interaction-dependent exposure with limited confidentiality impact and no integrity or availability impact.
Defensive priority
Medium for privacy-sensitive deployments, otherwise low. The issue does not indicate code execution or device compromise, but it can defeat an expected VPN privacy boundary under specific settings.
Recommended defensive actions
- Update GrapheneOS to build 2026050400 or later.
- Review device policy for Always-on VPN and Block connections without VPN on any GrapheneOS systems that depend on strict VPN routing.
- Treat the issue as a privacy exposure and verify whether any apps or workflows depend on the affected UDP path.
- Monitor official GrapheneOS release notes and CVE references for any follow-up guidance or related fixes.
Evidence notes
This debrief is based only on the supplied CVE record and the references listed in that record. The record states the affected condition, the build boundary (before 2026050400), the VPN settings involved, and the low confidentiality-only impact. No unsupported exploit steps or external claims were added.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-45182 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-45182
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-45182 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-45182
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://cyberinsider.com/grapheneos-fixes-android-vpn-leak-google-refused-to-patch/
-
Source reference
Unverified legacy reference
URL: https://grapheneos.org/releases
-
Source reference
Unverified legacy reference
URL: https://lowlevel.fun/posts/tiny-udp-cannon-android-vpn-bypass/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.