Turns out your router can receive a DHCP option 121 and have its routes modified by it. If you’re routing some traffic via VPN or by other means, such a route could be overridden. If course these days most traffic is e2e encrypted, so it’s less likely that your information will leak, but it is possible. You do encrypt DNS, right?
Could you adapt the title mentioning the CVE from your source ? That would probably draw some attention *TunnelVision (CVE-2024-3661):
I'm not affected too much by this because I do not use a kill switch. Traffic goes over the VPN or otherwise is blocked by the firewall. IIRC my router only allows NTP and DHCP from the ISP (very minimal) all other data goes through the tunnel. I have to do some testing to see what it does exactly.
But nevertheless I was really surprised Android of all OS's was not affected by this
I'm really looking forward to the dev comments about this.
Thanks for digging that up; seems like such an ez fix for something thats gonna burn a lot of people. Starlink pushes this when you bypass their modem "to maintain access to their system" but idk, they could like stop at the dish, right?
I saw this suggested elsewhere:
Comment out line 39 in