icon

We found results for “

CVE-2024-34446

Good to know:

icon

Date: May 2, 2024

Mullvad VPN through 2024.1 on Android does not set a DNS server in the blocking state (after a hard failure to create a tunnel), and thus DNS traffic can leave the device. Data showing that the affected device was the origin of sensitive DNS requests may be observed and logged by operators of unintended DNS servers.

Language: RUST

Severity Score

Severity Score

Weakness Type (CWE)

Improper Restriction of Communication Channel to Intended Endpoints

CWE-923

Top Fix

icon

Upgrade Version

Upgrade to version 0c39306a40f426853d617e20d596942e41091f13

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us