Welcome to the Off-Shore Club

The #1 Social Engineering Project in the world since 2004 !

Breaking News Mullvad VPN: macOS sometimes leaks traffic after system updates

Gold

Maksim

Tactician
Staff member
Administrator
Instructor
USDT(TRC-20)
$450.0
We have found that you could be leaking traffic on macOS after system updates. To our current knowledge a reboot resolves it. We are currently investigating this and will follow up with more information.


The current state​


In this scenario the macOS firewall does not seem to function correctly and is disregarding firewall rules. Most traffic will still go inside the VPN tunnel since the routing table specifies that it should. Unfortunately apps are not required to respect the routing table and can send traffic outside the tunnel if they try to. Some examples of apps that do this are Apple’s own apps and services since macOS 14.6, up until a recent 15.1 beta.


What’s next?​


We’ve reported this to Apple and hopefully we’ll see a fix in the near future. In the meanwhile we will continue to investigate this to be able to provide more information to Apple and to see if there are any workarounds that we can implement in the app.


Check if you are affected​


Run the following commands in a terminal to check if you are affected:


1. Add a firewall rule that blocks all traffic




2. Try to send traffic outside the tunnel



To clean up after the experiment, disable the firewall and clear all rules.



It is also possible to check if our app is leaking by doing the following:


1. Make sure you are not connected to a VPN
2. Find the default interface by running the following command in a terminal

route get mullvad.net | sed -nE 's/.*interface: //p'

3. Connect to a VPN server using our app

4. Run the following command (replace “<interface>” with the interface from step 2)

curl --interface <interface> https://am.i.mullvad.net/connected

5. The request should time out if everything is working properly. If there is a response then you are leaking.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Friendly Disclaimer We do not host or store any files on our website except thread messages, most likely your DMCA content is being hosted on a third-party website and you need to contact them. Representatives of this site ("service") are not responsible for any content created by users and for accounts. The materials presented express only the opinions of their authors.
🚨 Do not get Ripped Off ! ⚖️ Deal with approved sellers or use RTM Escrow on Telegram
Gold
Mitalk.lat official Off Shore Club Chat


Gold

Panel Title #1

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Panel Title #2

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Top