Security researchers and reporting from Android Gadget Hacks have identified a bug in Android 16 that can silently expose VPN user traffic. If you rely on Android 16’s built-in VPN protections, you might be browsing right now without the protection you think you have, and there is no warning on screen when it happens.

What was found

The report from Android Gadget Hacks describes a flaw in Android 16 that can let traffic slip outside the VPN tunnel while the connection still shows as active. That distinction matters. This is not a bug in a specific VPN app that a provider can patch on its own. It sits at the operating system level, in the layer that is supposed to route every packet through the tunnel once a VPN is connected.

Exact technical details are thin at this point. There is no confirmed CVE number attached to the report, no published list of affected devices, and no confirmed patch timeline from Google. That is worth saying plainly rather than papering over: this is a real but still thinly-reported story, and the responsible move is to explain what is known, flag what is not, and give advice that protects you either way.

Why an OS-level leak is worse than an app-level one

Most VPN security stories involve a specific app doing something it should not, like leaking DNS requests or mishandling a config file. Those are fixable by picking a better provider or a better client. An OS-level bug is different, because it sits underneath the app entirely.

Your VPN app can be independently audited, use solid encryption, and behave exactly as advertised, and it still would not catch this kind of failure. If Android itself lets traffic escape the tunnel, the leak happens beneath the app’s visibility. The app still shows “Connected.” The lock icon still looks fine. Nothing tells you that some of your traffic just went out over your regular connection instead, unencrypted and tied to your real IP.

That silence is the actual danger here. A visible failure at least prompts you to stop and check. A silent one does not.

This is a separate issue from the mobile VPN app problems this site covered a couple of weeks ago in our writeup on the University of Michigan’s MVPNalyzer study, where researchers tested 281 Android VPN apps and found dozens leaking data outside the tunnel because of how those specific apps were built. That study was about bad app engineering. This Android 16 report is about the operating system itself, which means it can affect you even if you are running a well-built, properly audited VPN app.

The one setting that actually matters here: kill switch

If there is a single practical takeaway from this story, it is this: enable your VPN’s kill switch, and confirm that it is actually on.

A kill switch is a feature that blocks all internet traffic the moment your VPN connection drops or fails to route correctly, rather than letting your device quietly fall back to your regular, unprotected connection. It is built for exactly this scenario: a gap between what the VPN app is telling you and what is actually happening at the network level. If the tunnel fails, silently or otherwise, a working kill switch keeps you offline instead of exposed.

Android’s own “Always-on VPN” and “Block connections without VPN” settings look similar to a kill switch and are useful, but they are not a substitute for the kill switch built into a reputable VPN app. Relying only on the OS-level toggle, without a dedicated kill switch as backup, means you are trusting the same layer of the operating system that this bug reportedly affects. Layer both if you can.

Want to compare all VPNs side by side? Check our full VPN comparison table with scores across 18 criteria.

Providers with strong leak protection

Not every VPN implements kill switch and leak protection with the same rigor. Based on verified leak-protection data (IP, DNS, WebRTC, and general data leak protection), these providers score well and are reasonable picks if you are on Android and want a strong safety net:

ProviderRatingLeak protectionKill switch
NordVPN4.6/5Full (IP, DNS, WebRTC, data)Yes, on Android app
ProtonVPN4.3/5Full (IP, DNS, WebRTC, data)Yes, on Android app
Mullvad4.2/5Full (IP, DNS, WebRTC, data)Yes, on Android app
Surfshark4.1/5Full (IP, DNS, WebRTC, data)Yes, on Android app

A strong kill switch does not fix an OS-level bug by itself, but it is the single most relevant defense against exactly the kind of leak this report describes, because it does not depend on the OS routing traffic correctly. It depends on cutting your connection the instant something looks wrong.

What to actually do about it

A few concrete steps, none of which require waiting on a patch:

Turn on your VPN’s kill switch. Check your app’s settings now, do not assume it is already active by default. Most major providers put it under a “Connection” or “Advanced” settings tab.

Keep Android updated. If this bug gets a confirmed fix, it will arrive through a system update. Set your phone to install security patches automatically so you are not the last to get it.

Test for leaks periodically. Connect your VPN, then run a leak test to confirm your real IP and DNS requests are not showing through. Our guide to checking for VPN IP leaks walks through the process in a few minutes, and it is worth doing after any Android update, not just this one.

Do not rely solely on “always-on VPN” as your only safety net. Treat OS-level VPN settings as a helpful layer, not the whole defense. Pair them with your VPN app’s own kill switch, which is built specifically to catch failures like this.

For a deeper explanation of how kill switches work and why they matter beyond this specific bug, our kill switch explainer covers the mechanics in plain terms.

What we still do not know

To stay honest about the limits of this story: we do not have a confirmed CVE, a list of affected Android 16 builds or devices, or a confirmed patch date from Google. The original report comes from Android Gadget Hacks, and we will update this article as more technical detail becomes available. Treat this as an early signal worth acting on defensively, not a fully mapped vulnerability.

This also is not the first time a mobile OS update has quietly changed how VPN traffic gets handled. Version bumps on both Android and iOS have a track record of shifting networking behavior in ways that only surface once independent researchers or security reporters go looking, long after the update already shipped to millions of phones. That lag between release and discovery is exactly why a kill switch matters as a standing habit rather than a one-time reaction to a single headline. You will not always get a warning before the next one.

It is also a reminder that “VPN protection” is not one single guarantee that either holds or fails completely. It is a stack of separate pieces, the app, the OS networking layer, the protocol, the server, that all have to work correctly together. A weakness in any one layer can undercut the rest, even when everything else in the stack is doing exactly what it is supposed to do. Treating a kill switch as a mandatory layer, rather than an optional extra, is the practical response to that reality.

Our Verdict

An OS-level VPN leak is more dangerous than an app-level one because it can happen silently, underneath a perfectly good VPN app, with no warning on screen. Until Android 16 gets a confirmed fix, the single best defense is a working kill switch, paired with keeping your phone updated and testing for leaks periodically. Do not lean on "always-on VPN" alone. NordVPN and ProtonVPN both offer a reliable kill switch on Android and are solid picks if you want that safety net in place today.